idp3: Path does not chain with any of the trust anchors

TISSOT Jacques jacques.tissot at unifr.ch
Wed Nov 11 04:20:13 EST 2015


Hi,

I struggle with Root Cerficate (CA), and I don't know how to handle on my IDP a Root CA with his Sub-certificate Authority. I need them for ldap Authentication and attributes resolving.

I got the ERROR: Path does not chain with any of the trust anchors

But basically, I don't understand the difference between certificateTrust and keystoreTrust:

"certificateTrust: Uses the idp.authn.LDAP.trustCertificates property to load a resource containing the trust anchors (such as a file of PEM-format certificates)"
"keyStoreTrust : Uses the idp.authn.LDAP.trustStore property to load a keystore containing the trust anchors"

Q (which): which certificate should I use against the ldap servers: Root_CA, Sub_CA, Sub_CA chained ? And should I store also the server-side certificates issued to the ldap servers?

Q (where): where do I store the(se) certificate(s) ? In the /opt/shibboleth-idp/credentials/ directory as pem files or imported in the /opt/shibboleth-idp/credentials/cacerts keystore?

Sorry, it is not as clear as it seems to me.

Thanks for help

J. Tissot




More information about the users mailing list