empty certificatekeystorepassword for tomcat TLS ?
IAM David Bantz
dabantz at alaska.edu
Thu Apr 25 21:12:21 UTC 2024
Our IdP in tomcat 10 configuration for TLS connections has always included
a certificatekeystorepassword to use the (InCommon) TLS certificate.
This year our server team requested a certificate for the IdP with an empty
password.
What risk, if any, does that pose?
Should I request a newer certificate with non-null password?
David St Pierre Bantz
U Alaska
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240425/df2b7cc5/attachment.htm>
More information about the users
mailing list