OpenSSL advisory
Cantor, Scott
cantor.2 at osu.edu
Thu Jul 9 11:49:48 EDT 2015
The latest version I've shipped with the Windows SP is 1.0.2a, and this bug impacts 1.0.2b+, so aside from any custom builds or any OS versions that happen to have included buggy versions, the SP isn't impacted.
I believe it is vulnerable to a serious remote exploit if run with this OpenSSL version and default settings, however, so this is just a lucky break. I had already prepared a red alarm advisory before reading the fine print.
I would strongly suggest people consider turning PKIX off in the SP in shibboleth2.xml:
...metadata providers...
<TrustEngine type="ExplicitKey" />
...attribute extractors, etc....
If you don't have metadata imported with the Shibboleth KeyAuthority extension, this change cannot break anything.
I am strongly considering making that the implicit default in the forthcoming patch release, although that's a significant change for a patch. I think the risk of PKIX, and the limited use of it, may warrant that.
-- Scott
More information about the users
mailing list