idp3: Path does not chain with any of the trust anchors
TISSOT Jacques
jacques.tissot at unifr.ch
Wed Nov 11 04:20:13 EST 2015
Hi,
I struggle with Root Cerficate (CA), and I don't know how to handle on my IDP a Root CA with his Sub-certificate Authority. I need them for ldap Authentication and attributes resolving.
I got the ERROR: Path does not chain with any of the trust anchors
But basically, I don't understand the difference between certificateTrust and keystoreTrust:
"certificateTrust: Uses the idp.authn.LDAP.trustCertificates property to load a resource containing the trust anchors (such as a file of PEM-format certificates)"
"keyStoreTrust : Uses the idp.authn.LDAP.trustStore property to load a keystore containing the trust anchors"
Q (which): which certificate should I use against the ldap servers: Root_CA, Sub_CA, Sub_CA chained ? And should I store also the server-side certificates issued to the ldap servers?
Q (where): where do I store the(se) certificate(s) ? In the /opt/shibboleth-idp/credentials/ directory as pem files or imported in the /opt/shibboleth-idp/credentials/cacerts keystore?
Sorry, it is not as clear as it seems to me.
Thanks for help
J. Tissot
More information about the users
mailing list