LDAP connection failure to SHA-2 InCommon cert

Dave Bartholomew Dave.Bartholomew at csueastbay.edu
Fri Mar 25 18:52:38 EDT 2016


Thanks - I think I'm missing the new InCommon intermediate.
And I'll have a look at the AD server since it wouldn't surprise me if the
certs are not properly set up to send what's necessary.

Dave Bartholomew
Cal State University, East Bay
ITS
Dave.Bartholomew at csueastbay.edu
(510) 885 – 2324


-----Original Message-----
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Friday, March 25, 2016 1:59 PM
To: Shib Users
Subject: Re: LDAP connection failure to SHA-2 InCommon cert

On 3/25/16, 4:53 PM, "users on behalf of Dave Bartholomew"
<users-bounces at shibboleth.net on behalf of Dave.Bartholomew at csueastbay.edu>
wrote:



>Despite Java being “OK” is there an IdP limitation as to when a SHA-2
>signed cert on an LDAP server used for attribute retrieval is workable?

No.

Basic trust issue, the CA chain involved with those certs is complicated,
and keeping old clients working with those new certs requires additional
intermediates be installed on the server end, or you need to put the
appropriate CA into the trust store you're using on the client.

The real bug here is on the LDAP server, it's not including the right
intermediates on its end to keep it all working until clients are updated
with the SHA-2 CA.

-- Scott

-- 
To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net


More information about the users mailing list