<div dir="ltr">
<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-s1"> </span><span class="gmail-s2"><Start</span><span class="gmail-s3">TLS</span><span class="gmail-s2">TrustCredential </span><span class="gmail-s4">xsi</span><span class="gmail-s5">:</span><span class="gmail-s4">type</span><span class="gmail-s1">=</span><span class="gmail-s6">"security:X509ResourceBacked"</span><span class="gmail-s2"> <br></span><span class="gmail-s2"> </span><span class="gmail-s4">xmlns</span><span class="gmail-s5">:</span><span class="gmail-s4">security</span><span class="gmail-s1">=</span><span class="gmail-s6">"urn:mace:shibboleth:2.0:security"</span><span class="gmail-s2"> <br></span><span class="gmail-s6"> </span><span class="gmail-s4">id</span><span class="gmail-s1">=</span><span class="gmail-s7">"........."</span><span class="gmail-s6">><br></span><span class="gmail-s6"> </span><span class="gmail-s2"><</span><span class="gmail-s8">security</span><span class="gmail-s5">:</span><span class="gmail-s2">Certificate></span><span class="gmail-s6">/...CA.pem</span><span class="gmail-s2"></</span><span class="gmail-s8">security</span><span class="gmail-s5">:</span><span class="gmail-s2">Certificate><br></span><span class="gmail-s1"> </span><span class="gmail-s6"></Start</span><span class="gmail-s3">TLS</span><span class="gmail-s6">TrustCredential></span></blockquote><div><br></div><div><br></div><div><br></div><div><br></div><p class="gmail-p1">
</p></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Sep 9, 2016 at 6:35 AM, Rod Widdowson <span dir="ltr"><<a href="mailto:rdw@steadingsoftware.com" target="_blank">rdw@steadingsoftware.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">TLDR:<br>
How many people use anything other than X509ResourceBacked to secure their<br>
LDAP connection and if so what do they use?<br>
<br>
Long version:<br>
<br>
I’m looking for some user feedback on a simplification I am going to<br>
introduce with 3.3 whereby<br>
<br>
<resolver:DataConnector type="dc:LDAPDirectory" ….><br>
<br>
<dc:StartTLSTrustCredential xsi:type="sec:<wbr>X509ResourceBacked"…><br>
<sec: Certificate>/dir/file.xml</<wbr>sec:Certificate><br>
</dc:StartTLSTrustCredential><br>
<br>
Will become<br>
<br>
<DataConnector type="LDAPDirectory" trustFile="/dir/file.xml"><br>
<br>
In a similar manner to the way that we simplified configuring the<br>
SignatureValidation metadata filter in 3.0.<br>
<br>
Just as in that case the old style will still be there and supported for all<br>
3.x versions (and very possibly beyond).<br>
<br>
My questions are:<br>
- Do you use something other than “sec:X509ResourceBacked” to specify<br>
the StartTLSTrustCredential?<br>
- Do you use the StartTLSAuthenticationCredenti<wbr>al and if so what sec:<br>
type do you use?<br>
<br>
If you can respond here I’ll collate the answers and make a call on how much<br>
work to do.<br>
<br>
Thanks<br>
<span class="HOEnZb"><font color="#888888"><br>
Rod<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br></div>