<div dir="ltr">Hi<div><br></div><div>I have read the Shibboleth IDP wiki page on how to configure ldap ssl using java&#39;s own keystore and my tests worked fine that way using ldaps however I would like to use my own separate keystore somewhere else in the disk.</div>
<div><br></div><div>I tried using the &quot;sslSocketFactory&quot; on login.config to point to a JKS but that gives me some IO errors, also pointing to just the crt of the CA did not seem to work (Got certificate path errors even though I tried both with the client certificate and the CA certificate immediately under it). </div>
<div><br></div><div>Is it possible to use a separate keystore for both login and also for the attribute connector?</div><div><br></div><div>I should mention that this is on IDP 2.4 and that I am not using StartTLS, it is a straight ssl connection to the ldap server.</div>
</div>