LDAP connection failure to SHA-2 InCommon cert

Dave Bartholomew Dave.Bartholomew at csueastbay.edu
Tue Mar 29 14:52:35 EDT 2016


> The real bug here is on the LDAP server, it's not including the right
> intermediates on its end to keep it all working until clients are updated
> with the SHA-2 CA.

I checked the AD server and it's returning the correct certs (chain, up to
but excluding the root).
It works on 3.x and fails on 2.x against the same AD server with the new
cert.
I didn't see any "extra" associated certs in C:\Program
Files\Java\jre\lib\security\cacerts for 3.x (on Windows using embedded
Jetty).

Given that a change was that the earlier working cert had one intermediate
while the new failing one has two, it is possible that the Shib "chain
walking" code has an issue with more than one intermediate in earlier 2.x
versions but not in 3.2.1?

If not, any suggestions on where/how to dig deeper?
Thanks.

-- Dave


More information about the users mailing list