<div dir="ltr"><div class="gmail_default" style="font-family:"courier new",monospace">There is a file in ${IDP_HOME}/credentials/ldap-server.crt, just put the ldap server cert or root ca in that file. I often use openssl s_client against the ldaps port of the ldap server if you don't have direct access to the cert.</div></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><font face="monospace, monospace">Jeffrey E. Crawford<br>Enterprise Service Team<a href="mailto:jeffreyc@ucsc.edu" target="_blank"></a></font><div><font face="monospace, monospace"> ^ ^</font></div><div><font face="monospace, monospace"> / \ ^ / \ ^</font></div><div><font face="monospace, monospace"> / \/ \ / \ / \</font></div><div><font face="monospace, monospace"> / \/ \/ \</font></div><div><font face="monospace, monospace">/ \</font></div><div><font face="monospace, monospace"><br></font></div><div><font face="monospace, monospace">You have been assigned this mountain to prove to others that it *can* be moved.</font></div></div></div></div></div></div></div>
<br><div class="gmail_quote">On Wed, May 10, 2017 at 6:40 AM, Daniel Fisher <span dir="ltr"><<a href="mailto:dfisher@vt.edu" target="_blank">dfisher@vt.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><span class="">On Tue, May 9, 2017 at 8:21 PM, Ghilteras <span dir="ltr"><<a href="mailto:angelo@twilio.com" target="_blank">angelo@twilio.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">sorry to bump an old thread, but I'm facing this issue now for a PoC and I<br>
don't seem to be able to find the equivalent of ldap_tls_reqcert on SSSD in<br>
Shibboleth, not even in the beans of<br>
/opt/shibboleth-idp/conf/authn<wbr>/ldap-authn-config.xml<br>
<br>
so is there no way to disable hostname validation during ssl handshake?<br></blockquote><div><br></div></span><div>Are you using LDAPS or startTLS?</div><span class="HOEnZb"><font color="#888888"><div><br></div><div>--Daniel Fisher</div><div><br></div></font></span></div></div></div>
<br>--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br></blockquote></div><br></div>