DuoOIDC plugin testing with updated root CA bundle

Christopher Bongaarts cab at umn.edu
Thu May 8 20:32:55 UTC 2025


On 5/8/2025 12:16 PM, Philip Smart via users wrote:
> Testing the updated CA bundle can be challenging because it depends on 
> the API host configured for your client or integration. Since we don't 
> have access to all the hosts for testing, we would like to ask if 
> anyone would be willing to install the current snapshot of either 
> DuoOIDC plugin variant (as they use the same set of certificates) in a 
> development environment and test their integration. If you could do 
> that and share the results, we would greatly appreciate it. 

I don't have time to do this at the moment, but I can provide the 
(current) cert chain for our API hosts:

Certificate chain
  0 s:/C=US/ST=Michigan/L=Ann Arbor/O=Duo Security LLC/CN=*.duosecurity.com
    i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert SHA2 High 
Assurance Server CA
  1 s:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert SHA2 High 
Assurance Server CA
    i:/C=US/O=DigiCert Inc/OU=www.digicert.com/CN=DigiCert High 
Assurance EV Root CA

It's the same for both of our instances.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%



More information about the users mailing list