Skip to Content.
Sympa Menu

shibboleth-dev - Re: testing the one-hop validation scenario

Subject: Shibboleth Developers

List archive

Re: testing the one-hop validation scenario


Chronological Thread 
  • From: Derek Atkins <>
  • To:
  • Cc: Shibboleth Design Team <>
  • Subject: Re: testing the one-hop validation scenario
  • Date: 06 Jun 2003 16:11:06 -0400

Ok, so it's working now?

-derek


writes:

> At 1:28 AM -0700 6/6/03, RL 'Bob' Morgan wrote:
> >I bet it's because it's exactly the same cert as the one earlier in the
> >file called "Verisign/RSA Secure Server CA", so it probably barfs when
> >trying to add two roots with the same issuer/subject/etc.
> >
>
> more confirmation.....
>
> I removed the duplicate cert from my trust.xml file, and removed the
> KeyAuthority element for my origin machine.....
>
> leaving a KeyAuthority element for shib2 and a KeyAuthority element
> for incommon:pilot.....
>
> and I can now use my 1.0 origin against my 1.0 target
>
>

--
Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
Member, MIT Student Information Processing Board (SIPB)
URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH


PGP key available

------------------------------------------------------mace-shib-design-+
For list utilities, archives, subscribe, unsubscribe, etc. please visit the
ListProc web interface at

http://archives.internet2.edu/

------------------------------------------------------mace-shib-design--




Archive powered by MHonArc 2.6.16.

Top of Page