using a chain cert with LDAP connector?

Peter Schober peter.schober at univie.ac.at
Mon Mar 24 12:39:15 EDT 2014


* Peter Schober <peter.schober at univie.ac.at> [2014-03-24 17:30]:
> * Liam Hoekenga <liamr at umich.edu> [2014-03-24 17:18]:
> > Can you use chain certs with the LDAP connector?
> 
> Certainly.  Just make sure any trust anchors and intermediate CAs are
> in the trust store (keytool -list).  Or try using a seperate trust
> store as discussed in the archives (at least).

Sorry, obviously you've already seen the documentation which explains
all of that at
https://wiki.shibboleth.net/confluence/display/SHIB2/ResolverLDAPDataConnector
(I answered the above literally.)

Whether there's a way to use <StartTLSTrustCredential> to configure a
certificate chain for use inside a DataConnector I don't know.

Did you try several <security:Certificate> elements or having more
than once certificate in the file (in both possible orders)?
-peter


More information about the users mailing list