Error resolving principal name
Morris, Andi
amorris at cardiffmet.ac.uk
Fri Apr 17 03:43:05 EDT 2015
We don't do any SSL offloading with TMG, it is end to end encrypted and it seems to work ok. Happy to be contacted off list Dave if you want some pointers with TMG, unless Scott can offer more expert advice on the best practice ways to publish Shibboleth to the internet.
Cheers,
Andi
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: 16 April 2015 18:09
To: Shib Users
Subject: Re: Error resolving principal name
On 4/16/15, 11:22 AM, "Dave Perry" <Dave.Perry at hull-college.ac.uk> wrote:
>
>We are trying to deploy a v3 IdP behind forefront. Our admin is having issues making the port 8443 thing work at all.
You can't do that (and if you can, you really shouldn't). SPs using the back channel mostly rely on client authentication and that has to be end to end in most cases.
If you want to offload SSL, you really need to either get rid of the back channel or get any SPs to switch to message signing to authenticate requests.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
________________________________
[Cardiff Metropolitan University - 150 years of nurturing talent]<http://www.cardiffmet.ac.uk/cardiffmet150>
More information about the users
mailing list