<div dir="ltr"><div><div><div>Thank you for the answer ,<br></div>to be more clear , we have an external organization which use them IDP , and they want that the communication will be encrypted by a CA certificate.<br></div>i know that the SP-metadata can be filtered by a certificate , but we need the them IDP will not communicate with any other SP , just if we have them CA certificate .<br><br></div><div>so what i can add in my SP configuration especially in shibboleth2.xml in order to accept only a certified connexion .<br><br></div><div><br></div>thank you<br></div><div class="gmail_extra"><br><div class="gmail_quote">2015-01-12 15:03 GMT+00:00 Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">&gt; I have configured SP and IDP (shibboleth) to work together with a generated<br>
&gt; key-pair , normally we suppose that i have a Certificate from authority in the<br>
&gt; idp ; how can i use this certificate to make a secured communication<br>
&gt; between SP and IDP , (secure the metadata access , communication...).<br>
<br>
</span>You don&#39;t. That&#39;s the short version of the article Tom sent the link to.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
</font></span><div class="HOEnZb"><div class="h5"><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr"><i><font color="#0b5394" face="verdana, sans-serif"><b>EL OTMANI Samir</b></font></i><div><i><font color="#0b5394" face="verdana, sans-serif"><b>Ingénieur d&#39;Etat en Génie Informatique </b></font></i></div><div><i><font color="#0b5394" face="verdana, sans-serif"><b>Tel:+212 699 041 864</b></font></i></div></div></div>
</div>