IdP 3.1.0.1 TLS problems

Dave Bartholomew Dave.Bartholomew at csueastbay.edu
Wed Apr 8 18:21:59 EDT 2015


Shibboleth 3.1.0.1 64-bit

Windows Server 2012 R2

java version "1.8.0_31" (Oracle JDK)

AD on Windows Server 2008 R2, used for both authN and attribute retrieval



I'm having problems getting my LDAP connector working, but before going
into any details, I'd like to know if my following vanilla ldap.properties
configuration looks OK:



idp.authn.LDAP.ldapURL= ldap://ldapserver.school.edu:389

AD cert has CN and SAN = ldapserver.school.edu



idp.authn.LDAP.sslConfig= certificateTrust



idp.authn.LDAP.trustCertificates=
%{idp.home}/credentials/trusted-ldap-certs.crt

Has InCommon intermediate (which signed ldapserver.school.edu cert) at top
with AddTrust root on bottom).



I would expect it would look for a certificate with ldapserver.school.edu
as a SAN (or maybe CN is OK?) and then check to see that it’s trusted via
the certs in trusted-ldap-certs.crt.



Is the intermediate cert recommended/needed in trusted-ldap-certs.crt?



Thanks.



Dave Bartholomew

Cal State University, East Bay

ITS

Dave.Bartholomew at csueastbay.edu

(510) 885 – 2324
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150408/5349932f/attachment.html 


More information about the users mailing list