OpenSSL upgrade

Peter Schober peter.schober at univie.ac.at
Thu Mar 26 10:49:12 EDT 2015


* sarath upadrista <upadrista.sarath at gmail.com> [2015-03-26 14:50]:
>      I am using shibboleth 2.5.0 version,ExternalIdp and a custom Service
> Provider(Not Shibboleth SP)

Sorry, what software from the Shibboleth project are you using?
There is no Shibbolet IDP version 2.5.0 and you're not using the
Shibboleth SP.

> - Is Shibboleth IDP using any openSSL libraries?

There is no OpenSSL for Java, so no.

> - If I upgrade my OpenSSL version, certificate on my tomcat server,
> Is it required to upgrade the shibboelth IDP?

There's no connection whatsoever, but upgrading your IDP is never
wrong.

> - Can I directly update the public key at the
> 'KeyDescriptor>ds:X509Certificate' element on idp-metadata.xml? Will it
> effect any existing functionality?

That file should be be used by anything or anyone, unless you have a
broken trust model and tell others to regularly pull (unsigned)
metadata from your IDP. So "it depends".
-peter


More information about the users mailing list