<html><body><div dir="ltr">Our IdP in tomcat 10 configuration for TLS connections has always included a certificatekeystorepassword to use the (InCommon) TLS certificate.<div><br></div><div dir="ltr">This year our server team requested a certificate for the IdP with an empty password. </div><div dir="ltr"><br></div><div dir="ltr">What risk, if any, does that pose? </div><div dir="ltr">Should I request a newer certificate with non-null password?</div><div dir="ltr"><br></div><div dir="ltr">David St Pierre Bantz</div><div dir="ltr">U Alaska</div></div></body></html>