IdP failed to retrive metada (problem, possible solution, and good practice): javax.net.ssl.SSLPeerUnverifiedException: SSL peer failed hostname validation for name: null
Christian Munive
christian.munive at gmail.com
Thu Jul 24 18:11:56 EDT 2014
Thanks Scott. I'll stick to http for the metadata.
2014-07-24 16:36 GMT-05:00 Cantor, Scott <cantor.2 at osu.edu>:
> On 7/24/14, 5:27 PM, "Christian Munive" <christian.munive at gmail.com>
> wrote:
> >
> >My question is: Is this a bad practice?
>
> Yes. Just use http; you should sign the metadata, have a validUntil value,
> and enforce a limit on the validity period. If the SSL isn't part of the
> trust fabric, you shouldn't use it, it will create confusion, barriers to
> getting the metadata, and just generally be a pain.
>
> Or you can set the disregardSslCertificate flag and turn off the SSL
> checking. That is a global setting in V2 due to library limitations.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140724/157abc03/attachment-0001.html
More information about the users
mailing list