Shib IdP - Metadata Download and Java 1.7.0_85
Wolfgang Pempe
pempe at dfn.de
Thu Jul 23 05:50:40 EDT 2015
Am 23.07.2015 um 10:59 schrieb Peter Schober:
> * Brent Putman <putmanb at georgetown.edu> [2015-07-23 08:20]:
>> I'm flabbergasted.
>
> Indeed.
>
> Thanks everyone for checking, esp. Takeshi!
+1
a possible federation-wide workaround (though not really politically
correct) would be to add the md server's IPv4 and v6 addresses as SaNs
to the cert. Perhaps that's what I'll do if the problem spreads...
Thanks again,
Wolfgang
>
>> As an aside, I don't see how their own X509TrustManagerImpl endpoint
>> identification stuff (above) can work with this change, which is partly
>> why I think it might have been an unintentional side effect of other
>> changes. (Unless they do something even more egregious, like resolve
>> the hostname(s) from the cert to IP addresses and match against those.
>> Surely they can't be that daft...).
>
> That would just break the other 99.9% of the web, presumably.
>
> And people complain about Tomcat making breaking changes in patch
> releases... ;)
> -peter
>
--
---------------------------------------------------------------------
Wolfgang Pempe Phone : +49 711 63314-208
DFN-Verein, Geschäftsstelle Stuttgart Fax : +49 711 63314-133
Lindenspürstr.32 E-Mail : pempe at dfn.de
D-70176 Stuttgart WWW : http://www.dfn.de
---------------------------------------------------------------------
--------------------- Deutsches Forschungsnetz ----------------------
--------- Germany's National Research and Education Network ---------
---------------------------------------------------------------------
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4938 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://shibboleth.net/pipermail/users/attachments/20150723/1f2e8a00/attachment.p7s>
More information about the users
mailing list