TestShib.org: Issue with some URLs specified in the metadata.
Nate Klingenstein
ndk at internet2.edu
Thu Oct 22 12:04:37 EDT 2015
Corey,
I was just trying to use testshib.org<http://testshib.org/> to test an OpenAM SP setup and one thing I ran into is that some of the endpoint URLs in the testshib-providers.xml metadata file are referencing endpoints that have a self-signed SSL certificate for some reason. The problematic URLs are all referencing port 8443 instead of the standard 443 port for SSL.
Shibboleth has historically treated back-channel queries as separate services that use separate certificates to avoid the rollover issues that would be incurred by the use of shorter-lived certificates I’m personally fine with revisiting this, and my dogma indicates my preference to use a single port and certificate for all of this.
https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement
But, the Shibboleth development team is working right now to get all communication into the front channel. Since TestShib ultimately exists to help deployers test out what the development team builds, my priorities are set by the developers and the deployers, and this one is unlikely to change in the near term unless I hear a unified voice from those communities indicating a change of direction.
Take care,
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151022/5ae7a217/attachment.html>
More information about the users
mailing list