<div dir="ltr">The certificate in question here is the LDAP server certificate, not the web server certificate.<br><br><div class="gmail_quote">On Sun, Oct 21, 2012 at 3:05 PM, Mauro Minella [via Shibboleth] <span dir="ltr">&lt;<a href="/user/SendEmail.jtp?type=node&node=7582608&i=0" target="_top" rel="nofollow" link="external">[hidden email]</a>&gt;</span> wrote:<br>
<blockquote style='border-left:2px solid #CCCCCC;padding:0 1em' class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="im">

        &gt;&gt;&gt; You&#39;d only need to do that if the server certificate is not trustworthy. Obviously then you&#39;d have to provision trust in the server connection via other methods.
<br><br></div>My WEB server already owns an SSL certificated from GoDaddy; in fact, if I try navigating to <a href="https://shibidp.eduteamit.com" rel="nofollow" link="external" target="_blank">https://shibidp.eduteamit.com</a>, it&#39;s opened withouth any warnings. Anyway I tried adding the certificated to the keystore, but it tells me &quot;Certificate already exists in keystore under alias &lt;tomcat&gt;&quot;.
<br><br>However, if I leave &lt;useStartTLS=&quot;true&quot;&gt; in attribute-resolver.xml, the IDP server, the IDP application does not start (error 404 &quot;The requested resource () is not available.&quot;).
<br><br>Thanks for continued support
<br><br>Mauro
<br><div class="im"><br></div></blockquote></div></div>


        
        
        
<br/><hr align="left" width="300" />
View this message in context: <a href="http://shibboleth.1660669.n2.nabble.com/Re-shibidp-2-3-8-setup-error-idp-status-tp7582608.html">Re: shibidp 2.3.8 setup error idp/status</a><br/>
Sent from the <a href="http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html">Shibboleth - Users mailing list archive</a> at Nabble.com.<br/>