java-1.7.0.79 might break LDAP(S) on shibboleth 2.4.4
Cantor, Scott
cantor.2 at osu.edu
Fri Apr 17 10:20:56 EDT 2015
On 4/17/15, 9:55 AM, "Rich Graves" <rgraves at carleton.edu> wrote:
>Posting early to give y'all a head's up and maybe save myself some searching if one of you can say, "OF COURSE it broke you idiot, why didn't you read..."
Thank you, I was about to start testing Oracle's version.
>The RHEL6/CentOS6 package java-openjdk-1.7.0.79-2.5.5.1.el6_6 appears to break LDAP authentication for me (standard edu.vt.middleware.ldap.jaas.LdapLoginModule called from within shibboleth 2.2.4, tomcat6, MCB 1.1.4). I tried both LDAPS and LDAP+TLS. In case it's relevant, our LDAP server SSL certs are still SHA1-signed, but not valid past 2015.
>
>Several possibly relevant CVE's and other changes at https://rhn.redhat.com/errata/RHSA-2015-0807.html
Do you actually know what they changed that broke it?
-- Scott
More information about the users
mailing list