shibboleth-dev - RE: Tomcat and certificate validation for SSL
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: "'Chad La Joie'" <>, <>
- Subject: RE: Tomcat and certificate validation for SSL
- Date: Mon, 13 Jun 2005 20:24:43 -0400
- Organization: The Ohio State University
> Here's my question though, if we just pass the client-cert auth
> employing request on, with the SSL info in the appropriate headers, for
> the IdP to verify are we weakening the security that people expect from
> the client-cert authentication? Also, are the headers that we're
> placing this data in defined in a standard (HTTPS standard perhaps)?
The J2EE spec defines a request parameter where the certificate ends up.
It's not actually a header, in the normal sense. I have no idea how to
inject that, but presumably we'd be able to let Tomcat do that as usual.
As far as security, well, I would imagine you're right (though how many
people are we talking about?), but then again, couldn't we set things up so
that one vhost did this and another didn't?
> My only concern with all this is portability to other containers.
Yep.
-- Scott
- Tomcat and certificate validation for SSL, Chad La Joie, 06/13/2005
- RE: Tomcat and certificate validation for SSL, Scott Cantor, 06/13/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/13/2005
- RE: Tomcat and certificate validation for SSL, Scott Cantor, 06/13/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/14/2005
- RE: Tomcat and certificate validation for SSL, Scott Cantor, 06/13/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/13/2005
- Re: Tomcat and certificate validation for SSL, Tom Scavo, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Tom Scavo, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Tom Scavo, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/14/2005
- RE: Tomcat and certificate validation for SSL, Howard Gilbert, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Tom Scavo, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Tom Scavo, 06/14/2005
- Re: Tomcat and certificate validation for SSL, Chad La Joie, 06/14/2005
- RE: Tomcat and certificate validation for SSL, Scott Cantor, 06/13/2005
Archive powered by MHonArc 2.6.16.