<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Nov 7, 2017, at 8:57 PM, Baron Fujimoto <<a href="mailto:baron@hawaii.edu" class="">baron@hawaii.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><div class=""><blockquote type="cite" class="">Shibboleth Identity Provider Security Advisory [4 October 2017]<br class=""><br class="">[...]<br class=""><br class="">Recommendations<br class="">===============<br class="">All deployers affected should take at least one, and preferably both,<br class="">of the following steps:<br class=""><br class="">[...]<br class="">2. Copy the server's certificate (or more typically a CA) to a file<br class="">and reference it with the trustFile attribute.<br class=""></blockquote><br class="">Forgive the dumb question, but for the trustFile server certificate<br class="">referenced above in 2), which server is that? The IdP's X.509 cert?<br class=""></div></div></blockquote><div><br class=""></div>No, the LDAP server's cert (or CA for that cert is often the better choice.)</div><div><br class=""></div><div><br class=""></div><div class="">
<div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" class=""><br class=""></div><br class="Apple-interchange-newline">

</div>
<br class=""></body></html>