OpenWS library 1.5.6 requires TLS session resume to connect?
Randall,Matt
MRANDALL at CERNER.COM
Wed May 25 15:17:59 EDT 2016
>>We encountered a fairly esoteric problem in upgrading org.opensaml openws-1.5.5 to openws-1.5.6 in that we can no longer make SOAP calls (or fetch metadata) against TLS implementations that do not provide TLS session resume capabilities
Just to get back to the original point - as a maintainer of a myriad of projects, I understand and respect the EOL announcement for v2. That being said, the changes in 1.5.6 make it completely incompatible for SOAP communication against a TLS implementation that has disabled session tickets (and this is more common than one might think). It seems like that's at least a noteworthy warning to publish for anyone that decides to take that particular fix version, especially if they interoperate with a large number of implementations; as you probably know, it's not usually expected for a patch version to introduce incompatibility outside of the bug being fixed.
CONFIDENTIALITY NOTICE This message and any included attachments are from Cerner Corporation and are intended only for the addressee. The information contained in this message is confidential and may constitute inside or non-public information under international, federal, or state securities laws. Unauthorized forwarding, printing, copying, distribution, or use of such information is strictly prohibited and may be unlawful. If you are not the addressee, please promptly delete this message and notify the sender of the delivery error by e-mail or you may call Cerner's corporate offices in Kansas City, Missouri, U.S.A at (+1) (816)221-1024.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20160525/ec27d1ca/attachment.html>
More information about the dev
mailing list