Skip to Content.
Sympa Menu

shibboleth-dev - RE: 2.0 IdP w/NO apache, security policy fails

Subject: Shibboleth Developers

List archive

RE: 2.0 IdP w/NO apache, security policy fails


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: 2.0 IdP w/NO apache, security policy fails
  • Date: Wed, 12 Dec 2007 13:03:09 -0500
  • Organization: The Ohio State University

> Failed to validate untrusted credential against trusted key
>
> when processing the incoming SSO request.....
>
> My first wild guess would be that tomcat isn't passing the SPs cert
> on to the IdP in the same way that apache is... since the IdP is
> using the same metadata in both cases...

An SSO request doesn't need Apache or Tomcat to pass in the certificate,
it's inside the message (or it's a redirect and it isn't there ever).

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page