Shibboleth IDP 3 as CAS Server

Cantor, Scott cantor.2 at osu.edu
Thu Jun 11 17:24:52 EDT 2015


On 6/11/15, 9:21 PM, "Jesse Martinich" <martinicj at sou.edu> wrote:



>Thank you. I'm not sure which cert I should make sure I am trusting. 
>Using s_client just checks the ssl cert being used for Tomcat SSL. Don't 
>I need to make sure idp-signing.crt is being trusted?

Not for the callback, no. If you're hitting 443, it's the user facing 
cert. If you're hitting 8443, which I don't think you did, it would be the 
back channel cert. Both are configured in Jetty/Tomcat not the IdP.

-- Scott



More information about the users mailing list