IdP 3.1.0.1 TLS problems

Cantor, Scott cantor.2 at osu.edu
Thu Apr 9 14:39:59 EDT 2015


On 4/9/15, 2:32 PM, "Dave Bartholomew" <Dave.Bartholomew at csueastbay.edu> wrote:

>> how it decides what certificate to offer
>
>The pattern I saw was the <hostname>.school.edu and InCommon certs being
>sent to the client in the ACK to the "client hello" frame with the
>ldapserver.school.edu cert being sent in the "server hello" frame (which I
>would think would be sufficient for the IdP to do its validation).

It can't be both. The server only presents one chain to the client. And AFAIK, the client doesn't offer a list of CAs to the server (the reverse happens, but only on TLS client authn).

-- Scott



More information about the users mailing list