OpenSSL heartbleed bug / Shibboleth implications
Jeff Silverman
jeff at moodlerooms.com
Tue Apr 8 13:46:17 EDT 2014
Thanks for this discussion. I actually did know all this already, and we've
been discussing it thoroughly on my team -- I was just curious what the InC
recommendations were regarding certs in the InC Metadata. I posted that to
the InC Participants list, btw, so also, thanks for the clarification on
which list to post to.
Don't get me wrong -- this discussion is extremely useful.
Thank you everyone.
On Tue, Apr 8, 2014 at 1:32 PM, Andy Bennett <andyjpb at knodium.com> wrote:
> Hi Jeff,
>
> > I've tried due diligence before posting this question but the best
> > answer I can derive is "maybe"
> >
> > - We don't have any reason to believe we've been compromised
> > - We are only running Shib SP services
> > - We've applied patches to everything from our vendor
>
> You can only have been compromised if you are running a vulnerable
> version of the software.
>
> If you are in a position where you are running a vulnerable version of
> the software then you *may* have been compromised. As this attack is
> undetectable in logs then you should assume that you *have* been
> compromised and act accordingly. You should consider any data that the
> vulnerable process has access to be at large. This includes
> certificates, passwords and user data.
>
>
> The vulnerable versions of the software are:
>
> + OpenSSL 1.0.1 to 1.0.1f inclusive
>
> + 2.5.x versions of the Shibboleth SP
> package for Windows.
>
> ...and potentially others that I have missed.
>
> (Thanks to Ian Young for version info.)
>
> Earlier versions of OpenSSL are not vulnerable.
>
>
>
> Check out the following website for a (non Shibboleth related)
> explanation of the situation:
>
> http://heartbleed.com/
>
>
>
>
>
>
>
> Regards,
> @ndy
>
> --
> andyjpb at knodium.com
> http://www.knodium.com/
>
>
--
Jeffrey D. Silverman * Moodlerooms, Inc.
(410) 779-3425 * jeff at moodlerooms.com
--
This email and any attachments may contain confidential and proprietary
information of Moodlerooms that is for the sole use of the intended
recipient. If you are not the intended recipient, disclosure, copying,
re-distribution or other use of any of this information is strictly
prohibited. Please immediately notify the sender and delete this
transmission if you received this email in error.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140408/d35c1ab0/attachment-0001.html
More information about the users
mailing list