[JIRA] Commented: (SSPCPP-441) Libcurl versions before 7.20 do not refresh caches of IdP IP address look-ups - this breaks SAML1 attribute query if the IdP's IP address is changed
Scott Cantor (JIRA)
noreply at shibboleth.net
Tue Jun 26 16:17:55 BST 2012
[ https://issues.shibboleth.net/jira/browse/SSPCPP-441?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=14185#comment-14185 ]
Scott Cantor commented on SSPCPP-441:
-------------------------------------
Of course it's not that easy. Latest libcurl is not the same soname, it's now libcurl.so.4 and the version in RH5 is libcurl.so.3, so there's no way to build for the original and substitute the new one.
It's all or nothing, no choice.
I might be able to add a lifetime to the cached connections and stop using them after they expire. I don't know if that will fix it, but it would limit the connection pool from staying around forever and maybe that will allow the stale entries to expire during periods of less use. I don't know. There's not alot I can do here, the real fix is to ask Red Hat to backport the patch.
> Libcurl versions before 7.20 do not refresh caches of IdP IP address look-ups - this breaks SAML1 attribute query if the IdP's IP address is changed
> ----------------------------------------------------------------------------------------------------------------------------------------------------
>
> Key: SSPCPP-441
> URL: https://issues.shibboleth.net/jira/browse/SSPCPP-441
> Project: Shibboleth SP - C++
> Issue Type: Bug
> Environment: CentOS 5, RedHat 5, any other distribution that ships a version of libcurl before 7.20
> CentOS 6 and RedHat 6 are not affected, please see Description for reason why.
> Reporter: Sara Hopkins
> Assignee: Scott Cantor
> Fix For: 2.5
>
>
> Please see this shibboleth-users discussion, in particular the last six emails:
> http://groups.google.com/group/shibboleth-users/browse_thread/thread/03b347520659428c/1b866419a1198144?pli=1
> There is a bug in libcurl versions lower than 7.20 which means that once an IdP's IP address has been looked up for attribute query purposes, it is cached and no further DNS lookups are made for that hostname until the SP is restarted. The bug was fixed in libcurl 7.20 - http://daniel.haxx.se/blog/2010/02/09/a-big-curl-forward/ - and http://curl.haxx.se/changes.html
> So, if an IdP IP address is changed, and it runs up against this bug, the SP operator has to restart shibd to get things working again for that IdP/SP pair..
> I know that this is not an SP bug, but the problem is that the CentOS5/RedHat5 libcurl is only 7.15.5! This is something of a problem for operators of SPs on those platforms. But I know that the CentOS and RH6 platforms are not affected, even though they also ship a version of libcurl lower than 7.20, because of this:
> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPLinuxRH6
> Might I suggest that this solution is built for CentOS/RH5 as well, in order to work around this libcurl bug?
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list