Shibboleth Identity Provider Security Advisory [4 October 2017]

Michael A Grady mgrady at unicon.net
Tue Nov 7 22:01:05 EST 2017


> On Nov 7, 2017, at 8:57 PM, Baron Fujimoto <baron at hawaii.edu> wrote:
> 
>> Shibboleth Identity Provider Security Advisory [4 October 2017]
>> 
>> [...]
>> 
>> Recommendations
>> ===============
>> All deployers affected should take at least one, and preferably both,
>> of the following steps:
>> 
>> [...]
>> 2. Copy the server's certificate (or more typically a CA) to a file
>> and reference it with the trustFile attribute.
> 
> Forgive the dumb question, but for the trustFile server certificate
> referenced above in 2), which server is that? The IdP's X.509 cert?

No, the LDAP server's cert (or CA for that cert is often the better choice.)


--
Michael A. Grady
IAM Architect, Unicon, Inc.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171107/5362cf84/attachment.html>


More information about the users mailing list