[JIRA] Commented: (SSPCPP-441) Libcurl versions before 7.20 do not refresh caches of IdP IP address look-ups - this breaks SAML1 attribute query if the IdP's IP address is changed
Scott Cantor (JIRA)
noreply at shibboleth.net
Tue Jun 26 04:59:55 BST 2012
[ https://issues.shibboleth.net/jira/browse/SSPCPP-441?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14182#comment-14182 ]
Scott Cantor commented on SSPCPP-441:
-------------------------------------
Unfortunately, I think there's no reason this would work. I think you're seeing false results. The bug that was fixed in 7.20 is that it didn't overwrite expired entries if they're "in use" by connection handles in some cases. There was no bug in the actual timeout value used, and the default is 60, so using 120 would make them last even longer.
I think that there are probably race conditions involved in whether the entry gets "stuck" or not, and your test just didn't happen to make it stick. At least that's my best guess.
Probably the best thing to do is what you suggested originally, have me publish a curl-openssl binary with the more recent version for the other repositories, and just document that people can choose to install and enable it using the /etc/sysconfig/shibd file added in the new version.
> Libcurl versions before 7.20 do not refresh caches of IdP IP address look-ups - this breaks SAML1 attribute query if the IdP's IP address is changed
> ----------------------------------------------------------------------------------------------------------------------------------------------------
>
> Key: SSPCPP-441
> URL: https://issues.shibboleth.net/jira/browse/SSPCPP-441
> Project: Shibboleth SP - C++
> Issue Type: Bug
> Environment: CentOS 5, RedHat 5, any other distribution that ships a version of libcurl before 7.20
> CentOS 6 and RedHat 6 are not affected, please see Description for reason why.
> Reporter: Sara Hopkins
> Assignee: Scott Cantor
> Fix For: 2.5
>
>
> Please see this shibboleth-users discussion, in particular the last six emails:
> http://groups.google.com/group/shibboleth-users/browse_thread/thread/03b347520659428c/1b866419a1198144?pli=1
> There is a bug in libcurl versions lower than 7.20 which means that once an IdP's IP address has been looked up for attribute query purposes, it is cached and no further DNS lookups are made for that hostname until the SP is restarted. The bug was fixed in libcurl 7.20 - http://daniel.haxx.se/blog/2010/02/09/a-big-curl-forward/ - and http://curl.haxx.se/changes.html
> So, if an IdP IP address is changed, and it runs up against this bug, the SP operator has to restart shibd to get things working again for that IdP/SP pair..
> I know that this is not an SP bug, but the problem is that the CentOS5/RedHat5 libcurl is only 7.15.5! This is something of a problem for operators of SPs on those platforms. But I know that the CentOS and RH6 platforms are not affected, even though they also ship a version of libcurl lower than 7.20, because of this:
> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPLinuxRH6
> Might I suggest that this solution is built for CentOS/RH5 as well, in order to work around this libcurl bug?
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list