old certificate
Rod Widdowson
rdw at steadingsoftware.com
Mon Mar 28 06:14:30 EDT 2016
> Can I trust this test?
Yes, Shibboleth uses certificates in these circumstances only as containers for keypairs.
OTOH, it's usually a bad idea to leave your setup like that for any length of time. A number of commercial vendors look at the certificate contents as well as the contents of the metadata file (which is the canonical answer for correctness) when deciding to trust key pairs.
Since you have Apache in the loop you may have a backchannel set up via Apache. Beware that the invocation to apache to not do any checking and just pass the material on has a track record of not doing so. So beware there.
/Rod
More information about the users
mailing list