<html><head><meta http-equiv="content-type" content="text/html; charset=utf-8"></head><body dir="auto">IdP 3.4.6 java 8.5.55<div><div><br></div><div>Trust configured in JAAS config with explicitly trusted CAs in PEM trust file. </div><div><br></div><div>[Primary authN ldap servers used (7 AD DCs in 4 domains) use private CAs; this failover proxy is the exception using “known” CA, but I used the same strategy: its CA - and now server cert itself - are both in the same file as the private CAs.</div><div><br></div><div>This is the only one of 11 ldap services using “ldaps” - AD DCs all use StartTLS; other proxies use ldap.]<br><br><div dir="ltr"><div>David.Bantz<span class="Apple-style-span" style="-webkit-composition-fill-color: rgba(175, 192, 227, 0.231373); -webkit-composition-frame-color: rgba(77, 128, 180, 0.231373); ">@Alaska.edu</span><div><span class="Apple-style-span" style="-webkit-composition-fill-color: rgba(175, 192, 227, 0.230469); -webkit-composition-frame-color: rgba(77, 128, 180, 0.230469);"><br></span></div></div></div><div dir="ltr"><br><blockquote type="cite">On Jun 3, 2020, at 04:39, Daniel Fisher:<br></blockquote></div><blockquote type="cite"><div dir="ltr"><div dir="ltr"><div class="gmail_quote"><div><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">Do you want to configure trust as part of the JAAS config or are you attempting to use the default JVM trust? Also, just to confirm, we're talking about IDPv3?</div><div class="gmail_default" style="font-family:verdana,sans-serif"><br></div><div class="gmail_default" style="font-family:verdana,sans-serif">--Daniel Fisher</div><div class="gmail_default" style="font-family:verdana,sans-serif"></div></div></div>
<br></div></blockquote></div></div></body></html>