On Thu, Nov 15, 2012 at 11:59 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="im">On 11/15/12 11:54 AM, &quot;Peter Schober&quot; &lt;<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>&gt; wrote:<br>
<br><br>
</div>I get that part, but if you&#39;ve done the work to make SSL on the vhost<br>
possible, why turn it off for the app? 10 years ago, yes, for performance,<br>
but today?<br>
<span class="HOEnZb"><font color="#888888"><br></font></span></blockquote><div><br></div><div>for myself, i&#39;m trying to avoid overhead for cert maintenance and associated cost ... limited staff and resources</div><div>
where we have sensitive data going over the wire, we do use SSL on each vhost<br></div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="HOEnZb"><font color="#888888">
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>