<div dir="ltr">On Tue, Jun 25, 2013 at 9:32 AM, Glenn Wearen <span dir="ltr"><<a href="mailto:glenn.wearen@heanet.ie" target="_blank">glenn.wearen@heanet.ie</a>></span> wrote:<br><div class="gmail_extra"><div class="gmail_quote">
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-color:rgb(204,204,204);border-left-style:solid;padding-left:1ex"><div style="word-wrap:break-word">I hit this issue a few weeks ago, I tried switching off SSL hostname checks but ended up having to switch to plain ldap as the IdP (or the vt ldap library) assumed that the cert offered on AD server 1 should also be trusted on AD server 2 and rejects the cert offered by AD server 2.<div>
I should have logged a bug but didn't.</div><div><br></div></div></blockquote><div><br></div><div style>Please file a bug: <a href="https://issues.shibboleth.net/jira/browse/SIDP">https://issues.shibboleth.net/jira/browse/SIDP</a></div>
<div style>That configuration should be supported.</div><div style><br></div><div style>--Daniel Fisher</div><div style> </div></div></div></div>