Shib IdP - Metadata Download and Java 1.7.0_85
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 22 10:07:44 EDT 2015
On 7/22/15, 8:14 AM, "users on behalf of Wolfgang Pempe" <users-bounces at shibboleth.net on behalf of pempe at dfn.de> wrote:
>This behaviour seems to go back to a security fix which is described at
>http://www.oracle.com/technetwork/java/javase/7u85-relnotes-2587591.html
>(end of the page).
I thought that bug had to do with an odd quirk that was allowing Java to validate connections to systems based on IP address by looking up the name and then matching that the certificate. Unless your connection URL included an IP address, that wouldn't apply, so one of us is confused.
Either way, as far as I knew, we're doing our own hostname checking anyway, unless you're running an older version (and even then I thought it was being done by another library, not Java's verifier, but I could be wrong on that).
Signed metadata with appropriate validUntil constraints can be hosted with or without TLS and with no hostname check.
>Even though the workaround is obvious (-Djdk.tls.trustNameService=true),
If that fixes this, then I'm totally lost.
>
>I'm wondering whether this is an intended feature (well, should better
>ask the java developers) which may presumably cause many other web
>applications to 'break' - or do we have to deal with a Shib IdP-specific
>problem?
I'm not sure I understand the question there, maybe you can rephrase.
Brent would have to address my confusion, and what code's really being used where, but unless this is a supported IdP version, that would obviously be step one in terms of providing a consistent answer.
-- Scott
More information about the users
mailing list