Shibboleth Identity Provider and OpenSAML-J Security Advisory - [25 February 2015]

Cantor, Scott cantor.2 at osu.edu
Thu Feb 26 18:25:44 EST 2015


On 2/26/15, 6:20 PM, "Wessel, Keith" <kwessel at illinois.edu> wrote:

>Thanks for the very detailed write-up of this, Brent.
>
>A question: if the certificate in the keyauthority block of metadata 
>isn't actually used to sign any of the entities' certificates, is there 
>still a problem?

Yep.

> All of our SPs are instructed to use long-lived self-signed 
>certificates, and we verify that they are using such certificates before 
>we approve them. Our regional federation metadata still contains a 
>keyauthority block, but the cert in that block has nothing to do with any 
>of those self-signed certs, obviously.

Doesn't matter, the bug turns anything signed by that CA into a valid key 
for anything it applies to.

-- Scott



More information about the users mailing list