RemoteUser and X509 client certificate
ofaklintrafo
ofa at klintra.fo
Tue Jan 23 10:20:08 EST 2018
Thank you Ian for the response.
I agree that data be consistent. Measures must be taken to ensure that
there are no active client certificates which do not have associated
attributes in the attribute store. The certificate profile also includes an
OCSP responder URL and I have set the "SSLOCSPEnable on" in the apache
config and tested that it works as expected.
First I think I will take a closer look at the interceptors and try to add
an interceptor which will check if the attribute lookup has been successful.
--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html
More information about the users
mailing list