<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><br class="Apple-interchange-newline"><blockquote type="cite"><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">Date: Wed, 31 Jul 2013 17:11:08 +0200</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">From: Peter Schober &lt;</span><a href="mailto:peter.schober@univie.ac.at" style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; ">peter.schober@univie.ac.at</a><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">&gt;</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">Subject: Re: login.config to use private-CA-issued certificate<br></span></blockquote>...<br><blockquote type="cite"><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">You said those server certs were issued by a private CA, I'm assuming</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">the same one. Why not add that private CA as a trust anchor (via</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">whatever mechanism) instead of adding server certs, which will break</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">the next time someone decides to roll over a server cert (probably</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">without telling you)?</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "><span style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; display: inline !important; float: none; ">-peter</span><br style="font-family: Helvetica; font-size: medium; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; "></blockquote></div><br><div>This works&nbsp;and will definitely be more convenient,&nbsp;extensible and&nbsp;robust !</div><div>I've marked my calendar for the CA certificate expiration in October 2060 %-}</div><div><br></div><div>Mea culpa for 'mis-under-estimating' the capabilities of&nbsp;VT's middleware.</div><div><br></div><div><div>On Wed, 31 Jul 2013, at 06:10 , Christopher Bongaarts &lt;<a href="mailto:cab@umn.edu">cab@umn.edu</a>&gt; wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">Concatenate multiple CA certifcates into a single PEM file?</blockquote><br></div><div>I did think of that, but read that while "legal" it is not always supported:</div><div><br></div><div><span style="font-family: Times; ">"In almost all cases, OpenSSL will assume that there's only one certificate in a given file.&nbsp;</span></div><div><span style="font-family: Times; ">As such, it will generally only use the first certificate that it finds, and will ignore all others."</span></div><div><span style="font-family: Times; ">&nbsp;&lt;</span><a href="http://www.gagravarr.org/writing/openssl-certs/general.shtml">http://www.gagravarr.org/writing/openssl-certs/general.shtml</a>&gt;</div><div><br></div><div>db</div><div><br></div><div>login.config fragment:</div><div><br></div><div><div><font face="Andale Mono">ShibUserPassAuth {</font></div><div><font face="Andale Mono">...</font></div><div><font face="Andale Mono"><br></font></div><div><font face="Andale Mono">// UA AD Auth</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp;edu.vt.middleware.ldap.jaas.LdapLoginModule sufficient</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; ldapUrl="<a href="ldap://adua02.ua.ad.alaska.edu:3268">ldap://adua02.ua.ad.alaska.edu:3268</a> <a href="ldap://adua03.ua.ad.alaska.edu:3268">ldap://adua03.ua.ad.alaska.edu:3268</a>"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; baseDn="dc=ua,dc=ad,dc=alaska,dc=edu"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; bindDn="cn=uashib,ou=uaf_service,ou=uaf,dc=ua,dc=ad,dc=alaska,dc=edu"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; bindCredential="•••••••••••"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; subtreeSearch="true"</font></div><div><font face="Andale Mono">// Directly reference imported certificate for CA used to create/sign UA AD server certs&nbsp;</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; sslSocketFactory="{trustCertificates=file:/opt/shibboleth-idp/trustedcerts/UA_AD_CA.pem}"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; ssl="false"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; tls="true"</font></div><div><font face="Andale Mono">&nbsp; &nbsp; &nbsp; userField="sAMAccountName,uaIdentifier";</font></div><div><font face="Andale Mono"><br></font></div><div><font face="Andale Mono">};</font></div></div><div><br></div></body></html>