Shibboleth Identity Provider Security Advisory [4 October 2017]
Baron Fujimoto
baron at hawaii.edu
Wed Nov 15 13:33:33 EST 2017
On Thu, Nov 09, 2017 at 10:11:02PM +0000, Cantor, Scott wrote:
>> I'm not sure I understand this. The certificates have a validity period and
>> eventually expire. Isn't that to be expected and neither good or bad?
>
>Certificates don't need to expire annually, they do because people are hidebound in their thinking. But that's beside the point, as Mike said. If you need/want to trust a CA, then you can trust a CA. Just *trust* it by putting it into the configuration instead of assuming the right things will happen by default.
>
At the risk of beating a dead horse, this is what I think I understand the
situation to be based on the thread so far.
The trustfile can be the CA (bundle?). This is a better choice to use than
the cert for the LDAP host itself because you don't need coordinate
changes to the LDAP cert (e.g. expiration); the CA cert bundle is
typically kept updated with Java updates, so if you keep Java relatively
updated, this aspect is probably handled for you.
>> I feel like I don't really have enough context to
>> understand this. If there's IdP documentation that will give a better
>> grasp of this, I'd be happy if you could refer me to it.
>
>We haven't tried to document PKIX for anybody, it's not a Shibboleth thing. What we document is how to configure the trusted certificates, like most server software does, and the affected case is the LDAP DataConnector, so that's the relevant documentation. The simplest way to configure it in any recent version is with a simple "trustFile" attribute in the connector element. Put the CA in a file, point trustFile at it, done. It's that simple. That's what the advisory says, or at least it's what I thought it said.
Perhaps it was pretty self evident to others, but speaking just for
myself, just a little more context would have put me on firmer footing.
At least, identifying the certificate in question (for the LDAP host)
would have helped. Then, when presented with the option of the CA,
referring to it a a CA certificate or bundle and perhaps mentioning it as
a resource typically typically maintained with Java updates would have
also been helpful – presumably this is not uncommon. (Assuming I'm not
off in left field somewhere).
I'm just someone tasked with deploying and maintaining this service, but
it's just one of my responsibilities and I am demonstrably not as
steeped in the ins and outs of this as those that live and breathe this
stuff more intimately on a regular basis. Any breadcrumbs that help
lighten the cognitive load to sort this out is certainly appreciated.
--
Baron Fujimoto <baron at hawaii.edu> :: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum
More information about the users
mailing list