RemoteUser and X509 client certificate

ofaklintrafo ofa at klintra.fo
Tue Jan 23 10:20:08 EST 2018


Thank you Ian for the response.

I agree that data  be consistent. Measures must be taken to ensure that
there are no active client certificates which do not have associated
attributes in the attribute store. The certificate profile also includes an
OCSP responder URL and I have set the "SSLOCSPEnable on" in the apache
config and tested that it works as expected.

First I think I will take a closer look at the interceptors and try to add
an interceptor which will check if the attribute lookup has been successful.





--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html


More information about the users mailing list