Sibboleth SP v3.x Metadata Signature validation using PKIX trust engine question

Cantor, Scott cantor.2 at osu.edu
Tue Nov 14 13:11:09 UTC 2023


> DEBUG XMLTooling.TrustEngine.PKIX : unable to match DN, trying TLS
> subjectAltName match

That's a name failure, nothing to do with the root, or the path.

> Are you saying that you can add de CN/DN of an intermediate CA certificate
> as TrustedName and that then any certificates that are issue by the
> intermediate CA are trusted?

No, I'm saying if there was an intermediate it would have to be in the message to build the trust path, but you said there wasn't, and that's not the error anyway.

-- Scott




More information about the users mailing list