IdP 3.1.0.1 TLS problems
Cantor, Scott
cantor.2 at osu.edu
Thu Apr 9 14:39:59 EDT 2015
On 4/9/15, 2:32 PM, "Dave Bartholomew" <Dave.Bartholomew at csueastbay.edu> wrote:
>> how it decides what certificate to offer
>
>The pattern I saw was the <hostname>.school.edu and InCommon certs being
>sent to the client in the ACK to the "client hello" frame with the
>ldapserver.school.edu cert being sent in the "server hello" frame (which I
>would think would be sufficient for the IdP to do its validation).
It can't be both. The server only presents one chain to the client. And AFAIK, the client doesn't offer a list of CAs to the server (the reverse happens, but only on TLS client authn).
-- Scott
More information about the users
mailing list