Shibboleth Identity Provider Security Advisory [4 October 2017]
Michael A Grady
mgrady at unicon.net
Tue Nov 7 22:01:05 EST 2017
> On Nov 7, 2017, at 8:57 PM, Baron Fujimoto <baron at hawaii.edu> wrote:
>
>> Shibboleth Identity Provider Security Advisory [4 October 2017]
>>
>> [...]
>>
>> Recommendations
>> ===============
>> All deployers affected should take at least one, and preferably both,
>> of the following steps:
>>
>> [...]
>> 2. Copy the server's certificate (or more typically a CA) to a file
>> and reference it with the trustFile attribute.
>
> Forgive the dumb question, but for the trustFile server certificate
> referenced above in 2), which server is that? The IdP's X.509 cert?
No, the LDAP server's cert (or CA for that cert is often the better choice.)
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171107/5362cf84/attachment.html>
More information about the users
mailing list