<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<pre>Hi Daniel,</pre>
<pre>comment! :-)</pre>
<pre>As for login.config, it seems to have digested the addition (well, cannot say whether honored yet):</pre>
<pre class="prettyprint"><span class="pln">edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient
        host="my.host.domain"
        java</span><span class="pun">.</span><span class="pln">naming</span><span class="pun">.</span><span class="pln">ldap</span><span class="pun">.</span><span class="pln">factory</span><span class="pun">.</span><span class="pln">socket</span><span class="pun">="</span><span class="pln">javax</span><span class="pun">.</span><span class="pln">net</span><span class="pun">.</span><span class="pln">ssl</span><span class="pun">.</span><span class="typ">SSLSocketFactory"
        [...]
However, attribute-resolver.xml does not like that attribute in <resolver:DataConnector[@type="LDAPDirectory"] />....
</span>How would I go for setting the property you describe for the attribute resolver?
<span class="typ">
You understand, I am in the process of updating for a bunch of customers to 2.3.6, and if it
turns out that their LDAP cert was not correct I'll definitely need a quick possibility to revert
back to the old behaviour, ideally using solely config and not compiling anything...
Regards,
Martin
</span></pre>
<pre>
</pre>
<br>
<br>
Am 29.02.2012 18:24, schrieb Daniel Fisher:
<blockquote
cite="mid:CAFC6YwRp6xDTiB8Bmv-jYMTOaKUDjbqgtzhXsdhwYU304ziLJg@mail.gmail.com"
type="cite">On Wed, Feb 29, 2012 at 11:51 AM, Chad La Joie <span
dir="ltr"><<a moz-do-not-send="true"
href="mailto:lajoie@shibboleth.net">lajoie@shibboleth.net</a>></span>
wrote:<br>
<div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0 0 0
.8ex;border-left:1px #ccc solid;padding-left:1ex">
That said, there is a way to revert back to the old behavior
and I've<br>
asked Daniel to go ahead and document it on the vtldap site as
it's<br>
something you configure with that library.</blockquote>
<div><br>
</div>
<div>Here it is: <a moz-do-not-send="true"
href="http://code.google.com/p/vt-middleware/wiki/vtldapTLS#Hostname_Validation">http://code.google.com/p/vt-middleware/wiki/vtldapTLS#Hostname_Validation</a></div>
<div>Please comment if more explanation is needed.</div>
<div><br>
</div>
<div>--Daniel Fisher</div>
<div><br>
</div>
</div>
<br>
<fieldset class="mimeAttachmentHeader"></fieldset>
<br>
<pre wrap="">--
To unsubscribe from this list send an email to <a class="moz-txt-link-abbreviated" href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></pre>
</blockquote>
<br>
<pre class="moz-signature" cols="72">--
-----------------------------------------------------------------------
Dr. Martin Haase
DAASI International GmbH phone: +49 7071 407109-6
Europaplatz 3 Fax : +49 7071 407109-9
D-72072 Tübingen email: <a class="moz-txt-link-abbreviated" href="mailto:Martin.Haase@DAASI.de">Martin.Haase@DAASI.de</a>
Germany Web : <a class="moz-txt-link-freetext" href="http://www.daasi.de">http://www.daasi.de</a>
Directory Applications for Advanced Security and Information Management
-----------------------------------------------------------------------
</pre>
</body>
</html>