문제

From ADFS and ADFS 2.0 perspective is it possible to register Service Provider metadata that is using certificate (public key) that is not issued by signing authority ? I mean on self signing certificate.

도움이 되었습니까?

해결책

Yes - you can use a self-signed certificate for the SP and that certificate is reflected in the SP metadata.

So you can generate it with the Java keytool etc.

Also ensure that you generate the certificate for a reasonable period - at least a year otherwise you will have to co0ntinually update the metadata on the ADFS side.

다른 팁

It should not be as described in following document - Certificate Requirements for Federation Servers in section Determining your CA strategy

"ADFS does not require that certificates be issued by a CA. However, the SSL certificate (the certificate that is also used by default as the service communications certificate) must be trusted by the ADFS clients. We recommend that you not use self-signed certificates for these certificate types."

라이센스 : CC-BY-SA ~와 함께 속성
제휴하지 않습니다 StackOverflow
scroll top