java-1.7.0.79 might break LDAP(S) on shibboleth 2.4.4
Rich Graves
rgraves at carleton.edu
Fri Apr 17 09:55:47 EDT 2015
Posting early to give y'all a head's up and maybe save myself some searching if one of you can say, "OF COURSE it broke you idiot, why didn't you read..."
The RHEL6/CentOS6 package java-openjdk-1.7.0.79-2.5.5.1.el6_6 appears to break LDAP authentication for me (standard edu.vt.middleware.ldap.jaas.LdapLoginModule called from within shibboleth 2.2.4, tomcat6, MCB 1.1.4). I tried both LDAPS and LDAP+TLS. In case it's relevant, our LDAP server SSL certs are still SHA1-signed, but not valid past 2015.
Several possibly relevant CVE's and other changes at https://rhn.redhat.com/errata/RHSA-2015-0807.html
More information about the users
mailing list