SP Requires Signed IdP Cert...

Cantor, Scott cantor.2 at osu.edu
Fri Jan 30 00:49:39 EST 2015


> We are members of the Australian Access Federation (AAF) which expects
> us to use self-signed certificate with long expiry (as seems to be the
> case for most federations).  After consultation, they suggested it
> should be possible to configure a second certificate for this specific
> provider.

A back channel certificate is for TLS usage for SOAP. That's not so easy to add. You'd have to change your web server and add a second vhost with an alternate port or address.

> In relying-party.xml I have configured a security:Credential:

That isn't where you configure back channel credentials, that's a web server thing.

So you'd start by determining if they even know what they're asking for and if you're talking about the same thing.

-- Scott



More information about the users mailing list