Security Advisory 20120227
Chad La Joie
lajoie at shibboleth.net
Mon Feb 27 15:35:17 GMT 2012
Our testing with wildcard certs did not reveal any problem. From the
error message though, it looks as if the server is reporting itself as
'authorise-test.is.ed.ac.uk', which does not match a CN of
'*.authorise-test.is.ed.ac.uk'.
2.3.5 wouldn't exhibit this problem because it didn't check anything at
all. Hence the security issue.
On 2/27/12 10:28 AM, Mark Cairney wrote:
> Hi,
>
> There appears to be a problem with this and wildcard certificates- having tried it on one of our Test IDPs it bails out with the following error:
>
> 15:22:25.776 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109] - unabled to connect to the ldap
> javax.naming.CommunicationException: hostname of the server 'authorise-test.is.ed.ac.uk' does not match the hostname in the server's certificate.
>
> The entry in Java's keystore reads:
>
> Alias name: authorise-test
> Creation date: Feb 27, 2012
> Entry type: trustedCertEntry
>
> Owner: EMAILADDRESS=ext6033 at ed.ac.uk, CN=*.authorise-test.is.ed.ac.uk, OU=Information Services, O=University of Edinburgh, L=Edinburgh, ST=Scotland, C=GB
> Issuer: EMAILADDRESS=postmaster at ed.ac.uk, CN=The University of Edinburgh CA, OU=The University of Edinburgh, O=The University of Edinburgh, L=Edinburgh, ST=Scotland, C=GB
> Serial number: ce3
> Valid from: Thu Apr 28 14:20:45 BST 2011 until: Sun Apr 27 14:20:45 BST 2014
>
> Is this expected behaviour and are you aware of any workarounds? This setup was working fine with Shibboleth 2.3.5..
>
> Kind regards,
>
> Mark
>
>
> /*********************************
> Mark Cairney
> ITI UNIX Section
> Information Services
> University of Edinburgh
>
> Tel: 0131 650 6565
> Email: mark.cairney at ed.ac.uk
>
> *********************************/
>
>
More information about the users
mailing list