Security Advisory 20120227

Juan Quintanilla jquin014 at fiu.edu
Mon Feb 27 21:34:14 GMT 2012


Hi,

There is no load balancer performing the SSL-offloading on the shibboleth server  Below is the cert.

Owner: CN=*.fiu.edu, OU=Comodo PremiumSSL Wildcard, OU=Hosted by Florida International University, OU=Florida International University, O=Division of Information Technology, STREET=11200 SW 8th St, L=Miami, ST=FL, OID.2.5.4.17=33199, C=US

Also found some extra information when I turned on Debug for ldap:
16:25:56.858 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:123] -   hostname = fiuldap1.fiu.edu
16:25:56.859 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:124] -   cert = CN=rhldapc03.fiu.edu, OU=Division of Information Technology, O=Florida International University, L=Miami, ST=Alabama, C=US
16:25:56.871 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:197] - verifyDNS using subjectAltNames = []
16:25:56.872 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:214] - verifyDNS using CN = [rhldapc03.fiu.edu]
16:25:56.904 - DEBUG [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:163] - Error connecting to LDAP URL: ldaps://fiuldap1.fiu.edu

___________________
Juan Quintanilla
UTS - Enterprise Group
305-348-6573
jquin014 at fiu.edu<mailto:jquin014 at fiu.edu>
________________________________
From: users-bounces at shibboleth.net [users-bounces at shibboleth.net] on behalf of Daniel Fisher [dfisher at vt.edu]
Sent: Monday, February 27, 2012 4:18 PM
To: Shib Users
Subject: Re: Security Advisory 20120227

DEBUG logs for the edu.vt.middleware.ldap package would also be helpful.

On Mon, Feb 27, 2012 at 4:14 PM, Chad La Joie <lajoie at shibboleth.net<mailto:lajoie at shibboleth.net>> wrote:
Can you provide the cert?  Is there a load balancer performing
SSL-offloading involved at all?

On 2/27/12 4:01 PM, Juan Quintanilla wrote:
> Hi,
>
> I'm getting a similar error with connection to ldap.  We use a wild card cert *.fiu.edu<http://fiu.edu> and the message we receive is:
>
> 15:14:00.487 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109] - unabled to connect to the ldap
> javax.naming.CommunicationException: simple bind failed: fiuldap1.fiu.edu:636<http://fiuldap1.fiu.edu:636>
>
> Caused by: java.security.cert.CertificateException: Hostname '[fiuldap1.fiu.edu<http://fiuldap1.fiu.edu>]' does not match the hostname in the server's certificate
>
> Any ideas?
>
> Thanks!
> ___________________
> Juan Quintanilla
> UTS - Enterprise Group
> 305-348-6573<tel:305-348-6573>
> jquin014 at fiu.edu<mailto:jquin014 at fiu.edu>
> ________________________________________
> From: users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net> [users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net>] on behalf of Mark Cairney [mark.cairney at ed.ac.uk<mailto:mark.cairney at ed.ac.uk>]
> Sent: Monday, February 27, 2012 10:49 AM
> To: Shib Users
> Subject: Re: Security Advisory 20120227
>
> OK I've amended my config to point at one of the individual servers which does match the *.authorise-test.is.ed.ac.uk<http://authorise-test.is.ed.ac.uk> pattern and that seems to be working.
>
> authorise-test.is.ed.ac.uk<http://authorise-test.is.ed.ac.uk> is a round-robin DNS between 2 servers. We do have another identical round-robin DNS which does match the pattern- using this instead would be the simplest solution.
>
> Thanks,
>
> Mark
>
> On 27 Feb 2012, at 15:38, Cantor, Scott wrote:
>
>> On 2/27/12 10:28 AM, "Mark Cairney" <mark.cairney at ed.ac.uk<mailto:mark.cairney at ed.ac.uk>> wrote:
>>>
>>> 15:22:25.776 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109]
>>> - unabled to connect to the ldap
>>> javax.naming.CommunicationException: hostname of the server
>>> 'authorise-test.is.ed.ac.uk<http://authorise-test.is.ed.ac.uk>' does not match the hostname in the server's
>>> certificate.
>>
>> That doesn't match the wildcard you have here:
>>
>>> Owner: EMAILADDRESS=ext6033 at ed.ac.uk<mailto:ext6033 at ed.ac.uk>, CN=*.authorise-test.is.ed.ac.uk<http://authorise-test.is.ed.ac.uk>,
>>> OU=Information Services, O=University of Edinburgh, L=Edinburgh,
>>> ST=Scotland, C=GB
>>
>> That would be a bug to accept it.
>>
>>> Is this expected behaviour and are you aware of any workarounds? This
>>> setup was working fine with Shibboleth 2.3.5..
>>
>> That's because the library in 2.3.5 didn't verify it at all.
>>
>> I believe Daniel allowed for an override of the hostname verification via
>> a custom class. I don't know if there's a class built-in that literally
>> disables the check.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
>>
>
> /*********************************
> Mark Cairney
> ITI UNIX Section
> Information Services
> University of Edinburgh
>
> Tel: 0131 650 6565
> Email: mark.cairney at ed.ac.uk<mailto:mark.cairney at ed.ac.uk>
>
> *********************************/
>
>
> --
> The University of Edinburgh is a charitable body, registered in
> Scotland, with registration number SC005336.
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20120227/d23df5aa/attachment-0001.html 


More information about the users mailing list