Shibboleth Identity Provider Security Advisory [4 October 2017]

Michael A Grady mgrady at unicon.net
Wed Nov 22 11:27:32 EST 2017


> On Nov 21, 2017, at 9:41 PM, Baron Fujimoto <baron at hawaii.edu> wrote:
> 
> Reviewing the LDAPConnector page at
> <https://wiki.shibboleth.net/confluence/display/IDP30/LDAPConnector <https://wiki.shibboleth.net/confluence/display/IDP30/LDAPConnector>>
> suggests that the trustFile attribute is a feature of V3.3 (if that's what
> the superscripts mean)?
> 
> Given that we are using V3.2.1, does that mean our mitigation option,
> short of upgrading our IdP, is to replace the version of ldaptive inside
> the deployed warfile with the latest ldaptive version?

If not on 3.3, you can configure the trust certificate file by the previous approach, by adding the StartTLSTrustCredential element to your LDAP data connector, as per this (see example at bottom):

  https://wiki.shibboleth.net/confluence/display/IDP30/StartTLSTrustCredential

Add that after the FilterTemplate element (and after the ReturnAttributes element if you have one).

--
Michael A. Grady
IAM Architect, Unicon, Inc.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171122/91fb4b30/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 874 bytes
Desc: Message signed with OpenPGP
URL: <http://shibboleth.net/pipermail/users/attachments/20171122/91fb4b30/attachment-0001.sig>


More information about the users mailing list