tomcat6-dta-ssl does not work with Tomcat 6.0.43
Cantor, Scott
cantor.2 at osu.edu
Sat Apr 4 15:05:22 EDT 2015
On 4/4/15, 2:11 AM, "Takeshi NISHIMURA" <takeshi at nii.ac.jp> wrote:
>Shibboleth IdPv2's tomcat6-dta-ssl does not seem to work with Tomcat 6.0.43.
>In our environment, SAML Attribute Query always fails and the SP logs this error message.
>
>2015-03-10 15:47:42 ERROR Shibboleth.AttributeResolver.Query [3]: exception during SAML query to https://...:8443/idp/profile/SAML1/SOAP/AttributeQuery: CURLSOAPTransport failed while contacting SOAP endpoint (https://...:8443/idp/profile/SAML1/SOAP/AttributeQuery): error:14094416:SSL routines:SSL3_READ_BYTES:sslv3 alert certificate unknown
>2015-03-10 15:47:42 ERROR Shibboleth.AttributeResolver.Query [3]: unable to obtain a SAML response from attribute authority
>
>I think the signature change of getServerSocketFactory() would affect this issue.
That seems like an odd result unless there's something clearly pointing to this in the Tomcat log, but you can certainly file a bug (V2 IdP project is fine, we don't have separate ones for the plugins).
This is yet another example of why Tomcat should no longer be considered a good choice. Breaking an API in a patch release? Classic.
-- Scott
More information about the users
mailing list