Sibboleth SP v3.x Metadata Signature validation using PKIX trust engine question
Cantor, Scott
cantor.2 at osu.edu
Tue Nov 14 13:11:09 UTC 2023
> DEBUG XMLTooling.TrustEngine.PKIX : unable to match DN, trying TLS
> subjectAltName match
That's a name failure, nothing to do with the root, or the path.
> Are you saying that you can add de CN/DN of an intermediate CA certificate
> as TrustedName and that then any certificates that are issue by the
> intermediate CA are trusted?
No, I'm saying if there was an intermediate it would have to be in the message to build the trust path, but you said there wasn't, and that's not the error anyway.
-- Scott
More information about the users
mailing list