LDAP connection failure to SHA-2 InCommon cert

Dave Bartholomew Dave.Bartholomew at csueastbay.edu
Fri Mar 25 16:53:07 EDT 2016


We haven’t yet completed our move to Shib 3.2.1 on Windows and I found that
after an AD (our attribute store) cert renewal I got the following error
with the old version while 3.2.1 still worked:



16:16:58.336 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109] -
unabled to connect to the ldap

javax.naming.AuthenticationException: [LDAP: error code 49 - 80090308:
LdapErr: DSID-0C0903A9, comment: AcceptSecurityContext error, data 52e,
v1db1 ]



Given that the new cert was signed with SHA-2, that seems to be the likely
culprit although I’m not exactly sure where I should be looking. The old
Linux version is using Tomcat standalone as the container and is running
better than Java 1.4.2 which I understand is the floor for SHA-2 support.



Despite Java being “OK” is there an IdP limitation as to when a SHA-2
signed cert on an LDAP server used for attribute retrieval is workable?

Thanks for any pointers.



--Dave
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160325/5728d333/attachment.html>


More information about the users mailing list