Shib IDP's LDAPS attribute resolution and SSLv3
Dave Perry
Dave.Perry at hull-college.ac.uk
Thu Oct 16 04:41:35 EDT 2014
FWIW, our IdP binds to AD using a ldap:// URL and a service login we had created (same as other web services, like moodle) and then tries to do the login. No startTLS involved, and they're happy with that (IdP is in a DMZ, and has a translated IP address to access our domain controllers).
Dave
_________________________________________________
Dave Perry
eLearning Technologist, Hull College Group
Room L34 - Queens Gardens Library
Wilberforce Drive, Queen's Gardens, Hull, HU1 3DG
Extension 2230 / Direct Dial 01482 381930
* Need a fast reply? Try elearning at hull-college.ac.uk *
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Wessel, Keith
Sent: 15 October 2014 21:10
To: Shib Users
Subject: RE: Shib IDP's LDAPS attribute resolution and SSLv3
Thanks, Scott. I was afraid that'd be the answer.
My AD admin is suggesting we do our query over LDAP (cleartext) but with Kerberos-based LDAP authentication so we're not authenticating cleartext. I suspect the library's not capable of this, either. Does anyone know otherwise? Otherwise, time to see how AD handles starttls.
Keith
-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Wednesday, October 15, 2014 3:00 PM
To: Shib Users
Subject: Re: Shib IDP's LDAPS attribute resolution and SSLv3
On 10/15/14, 3:56 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>On 10/15/14, 3:30 PM, "Wessel, Keith" <kwessel at illinois.edu> wrote:
>
>>Hi, all,
>>
>>Our AD folks just turned off SSLv3 support on our AD LDAPS service.
>>Shib didn¹t like it.
>
>A little quick searching implies to me that the
>java.naming.security.protocol JNDI property is what controls this in
>Java, and the only value it appears to have is ssl [1]. Which probably
>means it doesn't support TLS.
Of course I find this strange and surprising, but if you're seeing it not work, I don't know what other conclusion to reach.
-- Scott
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
**********************************************************************
This message is sent in confidence for the addressee
only. It may contain confidential or sensitive
information. The contents are not to be disclosed
to anyone other than the addressee. Unauthorised
recipients are requested to preserve this
confidentiality and to advise us of any errors in
transmission. Any views expressed in this message
are solely the views of the individual and do not
represent the views of the College. Nothing in this
message should be construed as creating a contract.
Hull College owns the email infrastructure, including the contents.
Hull College is committed to sustainability, please reflect before printing this email.
**********************************************************************
TEXT
More information about the users
mailing list