SP Requires Signed IdP Cert...
Cantor, Scott
cantor.2 at osu.edu
Fri Jan 30 00:49:39 EST 2015
> We are members of the Australian Access Federation (AAF) which expects
> us to use self-signed certificate with long expiry (as seems to be the
> case for most federations). After consultation, they suggested it
> should be possible to configure a second certificate for this specific
> provider.
A back channel certificate is for TLS usage for SOAP. That's not so easy to add. You'd have to change your web server and add a second vhost with an alternate port or address.
> In relying-party.xml I have configured a security:Credential:
That isn't where you configure back channel credentials, that's a web server thing.
So you'd start by determining if they even know what they're asking for and if you're talking about the same thing.
-- Scott
More information about the users
mailing list