Security Advisory 20120227

Chad La Joie lajoie at shibboleth.net
Mon Feb 27 15:35:17 GMT 2012


Our testing with wildcard certs did not reveal any problem.  From the
error message though, it looks as if the server is reporting itself as
'authorise-test.is.ed.ac.uk', which does not match a CN of
'*.authorise-test.is.ed.ac.uk'.

2.3.5 wouldn't exhibit this problem because it didn't check anything at
all.  Hence the security issue.

On 2/27/12 10:28 AM, Mark Cairney wrote:
> Hi,
> 
> There appears to be a problem with this and wildcard certificates- having tried it on one of our Test IDPs it bails out with the following error:
> 
> 15:22:25.776 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109] - unabled to connect to the ldap
> javax.naming.CommunicationException: hostname of the server 'authorise-test.is.ed.ac.uk' does not match the hostname in the server's certificate.
> 
> The entry in Java's keystore reads:
> 
> Alias name: authorise-test
> Creation date: Feb 27, 2012
> Entry type: trustedCertEntry
> 
> Owner: EMAILADDRESS=ext6033 at ed.ac.uk, CN=*.authorise-test.is.ed.ac.uk, OU=Information Services, O=University of Edinburgh, L=Edinburgh, ST=Scotland, C=GB
> Issuer: EMAILADDRESS=postmaster at ed.ac.uk, CN=The University of Edinburgh CA, OU=The University of Edinburgh, O=The University of Edinburgh, L=Edinburgh, ST=Scotland, C=GB
> Serial number: ce3
> Valid from: Thu Apr 28 14:20:45 BST 2011 until: Sun Apr 27 14:20:45 BST 2014
> 
> Is this expected behaviour and are you aware of any workarounds? This setup was working fine with Shibboleth 2.3.5..
> 
> Kind regards,
> 
> Mark
> 
> 
> /********************************* 
> Mark Cairney
> ITI UNIX Section
> Information Services
> University of Edinburgh
> 
> Tel: 0131 650 6565
> Email: mark.cairney at ed.ac.uk
> 
> *********************************/
> 
> 


More information about the users mailing list