java-1.7.0.79 might break LDAP(S) on shibboleth 2.4.4

Daniel Fisher dfisher at vt.edu
Fri Apr 17 11:50:12 EDT 2015


On Fri, Apr 17, 2015 at 10:34 AM, Rich Graves <rgraves at carleton.edu> wrote:

> > Do you actually know what they changed that broke it?
>
> Nope, just checking if someone else had already run into this. Guess not.
>

I just upgraded on the Mac. Using the unlimited strength policy files, I
didn't see any issues performing some basic tests.


>
> I've got meetings next couple hours but will return to it in the
> afternoon. The RHSA mentions two crypto-ish things.
>
> Backing down the stack trace a little (I have *not* yet taken the time to
> look at what's in my trust store):
>
> Caused by: javax.net.ssl.SSLException: java.lang.RuntimeException:
> Unexpected error: java.security.InvalidAlgorithmParameterException: the
> trustAnchors parameter must be non-empty
>

Some things to check...
When you upgraded did you lose your cacerts file or is it corrupted?
Are you specifying a custom truststore/certificate in your LDAP config? Can
that still be read?

--Daniel Fisher
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150417/0fed7dd1/attachment.html 


More information about the users mailing list