Security Advisory 20120227

Chad La Joie lajoie at shibboleth.net
Mon Feb 27 21:14:43 GMT 2012


Can you provide the cert?  Is there a load balancer performing
SSL-offloading involved at all?

On 2/27/12 4:01 PM, Juan Quintanilla wrote:
> Hi,
> 
> I'm getting a similar error with connection to ldap.  We use a wild card cert *.fiu.edu and the message we receive is:
> 
> 15:14:00.487 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109] - unabled to connect to the ldap
> javax.naming.CommunicationException: simple bind failed: fiuldap1.fiu.edu:636
> 
> Caused by: java.security.cert.CertificateException: Hostname '[fiuldap1.fiu.edu]' does not match the hostname in the server's certificate
> 
> Any ideas?
> 
> Thanks!
> ___________________
> Juan Quintanilla
> UTS - Enterprise Group
> 305-348-6573
> jquin014 at fiu.edu
> ________________________________________
> From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Mark Cairney [mark.cairney at ed.ac.uk]
> Sent: Monday, February 27, 2012 10:49 AM
> To: Shib Users
> Subject: Re: Security Advisory 20120227
> 
> OK I've amended my config to point at one of the individual servers which does match the *.authorise-test.is.ed.ac.uk pattern and that seems to be working.
> 
> authorise-test.is.ed.ac.uk is a round-robin DNS between 2 servers. We do have another identical round-robin DNS which does match the pattern- using this instead would be the simplest solution.
> 
> Thanks,
> 
> Mark
> 
> On 27 Feb 2012, at 15:38, Cantor, Scott wrote:
> 
>> On 2/27/12 10:28 AM, "Mark Cairney" <mark.cairney at ed.ac.uk> wrote:
>>>
>>> 15:22:25.776 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109]
>>> - unabled to connect to the ldap
>>> javax.naming.CommunicationException: hostname of the server
>>> 'authorise-test.is.ed.ac.uk' does not match the hostname in the server's
>>> certificate.
>>
>> That doesn't match the wildcard you have here:
>>
>>> Owner: EMAILADDRESS=ext6033 at ed.ac.uk, CN=*.authorise-test.is.ed.ac.uk,
>>> OU=Information Services, O=University of Edinburgh, L=Edinburgh,
>>> ST=Scotland, C=GB
>>
>> That would be a bug to accept it.
>>
>>> Is this expected behaviour and are you aware of any workarounds? This
>>> setup was working fine with Shibboleth 2.3.5..
>>
>> That's because the library in 2.3.5 didn't verify it at all.
>>
>> I believe Daniel allowed for an override of the hostname verification via
>> a custom class. I don't know if there's a class built-in that literally
>> disables the check.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>>
> 
> /*********************************
> Mark Cairney
> ITI UNIX Section
> Information Services
> University of Edinburgh
> 
> Tel: 0131 650 6565
> Email: mark.cairney at ed.ac.uk
> 
> *********************************/
> 
> 
> --
> The University of Edinburgh is a charitable body, registered in
> Scotland, with registration number SC005336.
> 
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list