Skip to Content.
Sympa Menu

shibboleth-dev - Re: testing the one-hop validation scenario

Subject: Shibboleth Developers

List archive

Re: testing the one-hop validation scenario


Chronological Thread 
  • From:
  • To: Shibboleth Design Team <>
  • Subject: Re: testing the one-hop validation scenario
  • Date: Thu, 5 Jun 2003 22:11:07 -0400

At 9:37 PM -0400 6/5/03, Derek Atkins wrote:
"RL 'Bob' Morgan"
<>
writes:

I will leave the UW origin HS on shib.cac.washington.edu set up to use a
server cert issued by the UW CA. To test with it, a target would add the
UW site metadata to sites.xml, then add the UW CA to trust.xml in the
KeyAuthority section corresponding to the incommon pilot, ie with all the
other CA certs. Data below, also at

Now I'm a bit confused. It all just worked! The change I made:
failing to parse an X509 key out of the trust file (or failing to
insert it into a key store) is no longer a fatal operation. For some
reason it doesn't like the cert that calls itself /C=US/O=RSA Data
Security, Inc./OU=Secure Server Certification Authority.


well, that's truly odd, but very encouraging news!

can you tell if that RSA cert is "the same one" found in standard distributions (eg openssl bundle)?

------------------------------------------------------mace-shib-design-+
For list utilities, archives, subscribe, unsubscribe, etc. please visit the
ListProc web interface at
http://archives.internet2.edu/

------------------------------------------------------mace-shib-design--




Archive powered by MHonArc 2.6.16.

Top of Page