<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">
<div>
<div class="">
<div dir="ltr" class="">
<div class="">Corey,</div>
</div>
</div>
<br class="">
<blockquote type="cite" class="">
<div class="">
<div dir="ltr" class="">
<div class="">I was just trying to use <a href="http://testshib.org/" class="">testshib.org</a> to test an OpenAM SP setup and one thing I ran into is that some of the endpoint URLs in the testshib-providers.xml metadata file are referencing endpoints that
 have a self-signed SSL certificate for some reason.  The problematic URLs are all referencing port 8443 instead of the standard 443 port for SSL.<br class="">
</div>
</div>
</div>
</blockquote>
<div><br class="">
</div>
<div>Shibboleth has historically treated back-channel queries as separate services that use separate certificates to avoid the rollover issues that would be incurred by the use of shorter-lived certificates  I’m personally fine with revisiting this, and my
 dogma indicates my preference to use a single port and certificate for all of this.</div>
<div><br class="">
</div>
<div><a href="https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement" class="">https://wiki.shibboleth.net/confluence/display/CONCEPT/TrustManagement</a></div>
<div><br class="">
</div>
<div>But, the Shibboleth development team is working right now to get all communication into the front channel.  Since TestShib ultimately exists to help deployers test out what the development team builds, my priorities are set by the developers and the deployers,
 and this one is unlikely to change in the near term unless I hear a unified voice from those communities indicating a change of direction.</div>
<div><br class="">
</div>
<div>Take care,</div>
<div>Nate.</div>
</div>
</body>
</html>