STARTTLS cannot be enforced. It will be used automatically if the eğri server supports it. The encryption type should be takım to ‘None/STARTTLS’ in this case. See here for an example on how to configure self signed certificates. The native SAML integration negates the need for external software like Apache https://cuwip.ucsd.edu/members/sizesilica34/activity/1241077/