Shib IDP's LDAPS attribute resolution and SSLv3

Wessel, Keith kwessel at illinois.edu
Wed Oct 15 16:09:31 EDT 2014


Thanks, Scott. I was afraid that'd be the answer.

My AD admin is suggesting we do our query over LDAP (cleartext) but with Kerberos-based LDAP authentication so we're not authenticating cleartext. I suspect the library's not capable of this, either. Does anyone know otherwise? Otherwise, time to see how AD handles starttls.

Keith


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, October 15, 2014 3:00 PM
To: Shib Users
Subject: Re: Shib IDP's LDAPS attribute resolution and SSLv3

On 10/15/14, 3:56 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 10/15/14, 3:30 PM, "Wessel, Keith" <kwessel at illinois.edu> wrote:
>
>>Hi, all,
>> 
>>Our AD folks just turned off SSLv3 support on our AD LDAPS service. Shib
>>didn¹t like it.
>
>A little quick searching implies to me that the
>java.naming.security.protocol JNDI property is what controls this in Java,
>and the only value it appears to have is ssl [1]. Which probably means it
>doesn't support TLS.

Of course I find this strange and surprising, but if you're seeing it not
work, I don't know what other conclusion to reach.

-- Scott

-- 
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list