<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Apr 11, 2014 at 10:43 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div class="">&gt;B) the certificate/keypair use on port 4443 of the idp for back channel<br>
&gt;interaction<br>
<br>
</div>B normally runs on 8443, but certainly isn&#39;t limited to that. You have to<br>
apply generalities to your own deployment.<br>
<br>
B is the authentication credential for transport authentication of SOAP.<br>
<div class=""></div></blockquote></div><br></div><div class="gmail_extra">Would it be reasonable to consider using the front channel / browser facing cert to secure the backchannel?</div><div class="gmail_extra">What would be the downside?  (The calling SP would have to have the CA cert that was being used, right?)</div>

<div class="gmail_extra"><br></div><div class="gmail_extra">Liam</div></div>