> This is not exactly true. At least at the university in darmstadt we had a
> dual authentication stack allowing either x509 smartcards or ldap password
> lookups.

We have the same setup, but for x509 auth we use a special connector
with require="true" on an alt port, but all other connections to the
server, including ticket validation, happen on the non-client SSL
port.  Seems like a lot more configuration work to do client auth for
ticket validation due to the need to manage credentials on all your
clients.

M

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to