<blockquote style="margin:0pt 0pt 0pt 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote"><br>
No, it doesn't. Setting it to "want" means it's optional. And you haven't<br>
addressed the fact that all your access should be to port 443 and the<br>
client TLS is on port 8443 so they don't have any overlap anyway.<br><br></blockquote><div><br>I set it to "true". I think therefore the certificate was mandatory.<br><br></div><div class="gmail_quote">2012/6/18 Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span><br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 6/18/12 6:34 AM, "Stephan Hackstedt" <<a href="mailto:stephan.hackstedt@googlemail.com">stephan.hackstedt@googlemail.com</a>><br>
wrote:<br>
><br>
<div class="im">>the problem was, that when enabled clientAuth, the Client (Browser) needs<br>
>a PKAS Certificate.<br>
<br>
</div>No, it doesn't. Setting it to "want" means it's optional. And you haven't<br>
addressed the fact that all your access should be to port 443 and the<br>
client TLS is on port 8443 so they don't have any overlap anyway.<br>
<div class="im"><br>
>So I created one from the idp.jks file with openssl, added it to firefox<br>
>certificates and now it works.<br>
<br>
</div>That isn't why it works.<br>
<div class="im"><br>
>I'm wondering why SSLCertificateFile and SSLCertificateKeyFile don't have<br>
>a effect on the redirecting procedure.<br>
<br>
</div>Because that has nothing to do with your client. That's the server's<br>
certificate.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>