OpenSSL upgrade
Peter Schober
peter.schober at univie.ac.at
Thu Mar 26 10:49:12 EDT 2015
* sarath upadrista <upadrista.sarath at gmail.com> [2015-03-26 14:50]:
> I am using shibboleth 2.5.0 version,ExternalIdp and a custom Service
> Provider(Not Shibboleth SP)
Sorry, what software from the Shibboleth project are you using?
There is no Shibbolet IDP version 2.5.0 and you're not using the
Shibboleth SP.
> - Is Shibboleth IDP using any openSSL libraries?
There is no OpenSSL for Java, so no.
> - If I upgrade my OpenSSL version, certificate on my tomcat server,
> Is it required to upgrade the shibboelth IDP?
There's no connection whatsoever, but upgrading your IDP is never
wrong.
> - Can I directly update the public key at the
> 'KeyDescriptor>ds:X509Certificate' element on idp-metadata.xml? Will it
> effect any existing functionality?
That file should be be used by anything or anyone, unless you have a
broken trust model and tell others to regularly pull (unsigned)
metadata from your IDP. So "it depends".
-peter
More information about the users
mailing list