<blockquote style="margin:0pt 0pt 0pt 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex" class="gmail_quote"><br>
No, it doesn&#39;t. Setting it to &quot;want&quot; means it&#39;s optional. And you haven&#39;t<br>
addressed the fact that all your access should be to port 443 and the<br>
client TLS is on port 8443 so they don&#39;t have any overlap anyway.<br><br></blockquote><div><br>I set it to &quot;true&quot;. I think therefore the certificate was mandatory.<br><br></div><div class="gmail_quote">2012/6/18 Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span><br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 6/18/12 6:34 AM, &quot;Stephan Hackstedt&quot; &lt;<a href="mailto:stephan.hackstedt@googlemail.com">stephan.hackstedt@googlemail.com</a>&gt;<br>

wrote:<br>
&gt;<br>
<div class="im">&gt;the problem was, that when enabled clientAuth, the Client (Browser) needs<br>
&gt;a PKAS Certificate.<br>
<br>
</div>No, it doesn&#39;t. Setting it to &quot;want&quot; means it&#39;s optional. And you haven&#39;t<br>
addressed the fact that all your access should be to port 443 and the<br>
client TLS is on port 8443 so they don&#39;t have any overlap anyway.<br>
<div class="im"><br>
&gt;So I created one from the idp.jks file with openssl, added it to firefox<br>
&gt;certificates and now it works.<br>
<br>
</div>That isn&#39;t why it works.<br>
<div class="im"><br>
&gt;I&#39;m wondering why SSLCertificateFile and SSLCertificateKeyFile don&#39;t have<br>
&gt;a effect on the redirecting procedure.<br>
<br>
</div>Because that has nothing to do with your client. That&#39;s the server&#39;s<br>
certificate.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br>