Shibboleth Identity Provider Security Advisory [4 October 2017]
Baron Fujimoto
baron at hawaii.edu
Wed Nov 22 19:06:55 EST 2017
On Wed, Nov 22, 2017 at 08:59:52PM +0000, Cantor, Scott wrote:
>On 11/21/17, 10:42 PM, "users on behalf of Baron Fujimoto" <users-bounces at shibboleth.net on behalf of baron at hawaii.edu> wrote:
>
>> Given that we are using V3.2.1, does that mean our mitigation option,
>> short of upgrading our IdP, is to replace the version of ldaptive inside
>> the deployed warfile with the latest ldaptive version?
>
>Yes, but the solution is to patch your system. That should not even be a question, it's not optional.
Upgrading is definitely on our roadmap, but given our limited staffing,
internal policy constraints, and the plethora of other projects vying for
priority, we'd been planning tackle it down the road further.
However, if you, as a source we'd consider authoritative, are asserting
that it is not literally not optional to mitigate this security issue in
3.2.1 in the interim via one of suggested means, then we would be required
to reevaluate our current project prioritization and planning.
We know that best practice is to remain as current as possible with the
releases for all the services we support, but we don't have that luxury
given the resources at our disposal and so must compromise and acknowledge
the technical debt. We weigh our options and catch up when we can. Unless
we've missed something, I don't recall seeing anything to the effect that
continued use of 3.2.1 was unacceptable for some reason. If something to
this effect is out there, then that changes our calculus.
--
Baron Fujimoto <baron at hawaii.edu> :: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum
More information about the users
mailing list