<div dir="ltr"><div>I'm currently using a self-signed certificate for the SP Credential resolver, by config for this is same as the example:<br></div><div><br></div><div><CredentialResolver type="File" key="/etc/shibboleth/sp.key" certificate="/etc/shibboleth/sp.crt"/><br></div><div><br></div><div>This works fine, I have no login errors. However, I'm not clear on how this certificate is used. Am I opening myself up to spoofing attacks by using a self-signed certificate for this?</div><div><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><span style="font-size:12.8px">--Tom Noonan II</span><br></div></div></div></div></div></div>
</div></div>