error:0A000152:SSL routines::unsafe legacy renegotiation disabled with Shibboleth SP 3.4

Paul Henson henson at
Mon Nov 14 19:24:23 UTC 2022

On 11/14/2022 11:13 AM, Paul B. Henson wrote:
> That's up to curl, not OpenSSL. We do let it follow redirects,
> because we don't actually use the HTTP or even the TLS layer for
> securing the metadata. I did of course update curl on Windows also
> but that's not the sort of thing that would have changed.

Huh. Dunno. That problem is easily fixed by just removing the middleman, 
so I don't think it's worth worrying about.

Signet - The Art of Access

More information about the users mailing list