<div dir="ltr">I've just tried setting <span style="font-size:12.8px">extractNames="false", with no luck.</span></div><div class="gmail_extra"><br><div class="gmail_quote">On Thu, Mar 17, 2016 at 9:53 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">> Just in case, I've tried analyzing the certificate, and there is a statement:<br>
> X509v3 extensions:<br>
>             X509v3 Subject Alternative Name:<br>
</span>>                 DNS:<a href="http://zimbra.ntin.edu.tw" rel="noreferrer" target="_blank">zimbra.ntin.edu.tw</a> <<a href="http://zimbra.ntin.edu.tw" rel="noreferrer" target="_blank">http://zimbra.ntin.edu.tw</a>> ,<br>
> URI:<a href="https://my.host.name/shibboleth" rel="noreferrer" target="_blank">https://my.host.name/shibboleth</a><br>
<br>
Try adding extractNames="false" into the CredentialResolver.<br>
<span class="HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>