<div dir="ltr"><div><div>I wouldn't say that I fundamentally confuse that fact. I know that idp.authn.LDAP elements configure the authentication and idp.attribute.resolver elements configure attribute resolution and in most cases use the configuration from various authn defined elements.<br><br>idp.attribute.resolver.LDAP.useStartTLS = %{idp.authn.LDAP.useStartTLS:true}<br><br></div>For example, set useStartTLS to true unless idp.attribute.resolver.LDAP.useStartTLS is set authn, which it is set to false in my case.<br><br></div>Is there a idp.attribute.resolver.LDAP.useSSL setting because I can't find it in any template configurations or referenced in <a href="https://wiki.shibboleth.net/confluence/display/IDP30/LDAPConnector">https://wiki.shibboleth.net/confluence/display/IDP30/LDAPConnector</a>. I was under the incorrect assumption that having the url set to ldaps:// might be the trick but that also seems not to be the case.<br></div><br><div class="gmail_quote"><div dir="ltr">On Wed, Dec 6, 2017 at 12:17 PM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">On 12/6/17, 10:53 AM, "users on behalf of Darren Boss" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:darren.boss@computecanada.ca" target="_blank">darren.boss@computecanada.ca</a>> wrote:<br>
<br>
> I've got things running in DEBUG mode now and I'm super confused why my deployments are using the jvm truststore.<br>
<br>
I would imagine you're fundamentally confusing the fact that authentication and attribute resolution have nothing to do with each other and have separate configurations.<br>
<br>
> If I see this message on startup:<br>
<br>
Which is attribute resolution.<br>
<br>
> I am using<br>
> idp.authn.LDAP.sslConfig = certificateTrust<br>
<br>
Which is not attribute resolution.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div><div dir="ltr">-- <br></div><div class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><p style="margin-bottom:0in;line-height:100%"><font color="#ff0000"><font face="arial, sans-serif"><font style="font-size:10pt" size="2"><b>Darren
Boss</b></font></font></font></p><font style="font-size:10pt" size="2"><i>Senior Programmer/Analyst</i></font><font style="font-size:10pt" size="2"><i><br>Programmeur-analyste principal</i></font><font style="font-size:10pt" size="2"><i><br><a href="mailto:darren.boss@computecanada.ca">darren.boss@computecanada.ca</a></i></font><font style="font-size:10pt" size="2"><i><br>(o)
416.228.1234 x </i></font><font color="#000000"><font style="font-size:10pt" size="2">230<br></font></font></div><font color="#000000"><font style="font-size:10pt" size="2"><i>(c) 919.525.0083</i><br></font></font><div><font color="#000000"><font size="2"><br><span style="color:rgb(0,0,0);font-size:12.8px" class="gmail_msg">155 University Ave, Suite 302 Toronto, ON M5H 3B7</span><font class="gmail_msg" size="2"><br style="color:rgb(0,0,0)" class="gmail_msg"><span style="color:rgb(0,0,0)" class="gmail_msg"><a href="http://www.computecanada.ca" class="gmail_msg" target="_blank">www.computecanada.ca</a> / <a href="http://www.calculcanada.ca" class="gmail_msg" target="_blank">www.calculcanada.ca</a> </span><br style="color:rgb(0,0,0)" class="gmail_msg"><span style="color:rgb(0,0,0)" class="gmail_msg">@ComputeCanada </span></font><br style="color:rgb(0,0,0);font-size:medium" class="gmail_msg"><img style="color: rgb(0, 0, 0); font-size: medium;" class="gmail_msg" src="http://www.computecanada.ca/wp-includes/images/email_sig/cc_logo.jpg" width="200" height="120"><br></font></font></div></div></div>