OpenSSL advisory

Cantor, Scott cantor.2 at osu.edu
Thu Jul 9 11:49:48 EDT 2015


The latest version I've shipped with the Windows SP is 1.0.2a, and this bug impacts 1.0.2b+, so aside from any custom builds or any OS versions that happen to have included buggy versions, the SP isn't impacted.



I believe it is vulnerable to a serious remote exploit if run with this OpenSSL version and default settings, however, so this is just a lucky break. I had already prepared a red alarm advisory before reading the fine print.

I would strongly suggest people consider turning PKIX off in the SP in shibboleth2.xml:

...metadata providers...

<TrustEngine type="ExplicitKey" />

...attribute extractors, etc....

If you don't have metadata imported with the Shibboleth KeyAuthority extension, this change cannot break anything.

I am strongly considering making that the implicit default in the forthcoming patch release, although that's a significant change for a patch. I think the risk of PKIX, and the limited use of it, may warrant that.

-- Scott



More information about the users mailing list