<html dir="ltr">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style id="owaParaStyle" type="text/css">P {margin-top:0;margin-bottom:0;}</style>
</head>
<body ocsi="0" fpstyle="1">
<div style="direction: ltr;font-family: Book Antiqua;color: #000000;font-size: 12pt;">
Hi,<br>
<br>
There is no load balancer performing the SSL-offloading on the shibboleth server&nbsp; Below is the cert.<br>
<br>
Owner: CN=*.fiu.edu, OU=Comodo PremiumSSL Wildcard, OU=Hosted by Florida International University, OU=Florida International University, O=Division of Information Technology, STREET=11200 SW 8th St, L=Miami, ST=FL, OID.2.5.4.17=33199, C=US<br>
<br>
<div>Also found some extra information when I turned on Debug for ldap:<br>
16:25:56.858 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:123] -&nbsp;&nbsp; hostname = fiuldap1.fiu.edu<br>
16:25:56.859 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:124] -&nbsp;&nbsp; cert = CN=rhldapc03.fiu.edu, OU=Division of Information Technology, O=Florida International University, L=Miami, ST=Alabama, C=US<br>
16:25:56.871 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:197] - verifyDNS using subjectAltNames = []<br>
16:25:56.872 - DEBUG [edu.vt.middleware.ldap.ssl.DefaultHostnameVerifier:214] - verifyDNS using CN = [rhldapc03.fiu.edu]<br>
16:25:56.904 - DEBUG [edu.vt.middleware.ldap.handler.DefaultConnectionHandler:163] - Error connecting to LDAP URL: ldaps://fiuldap1.fiu.edu<br>
<br>
<div><font face="Book Antiqua">___________________<br>
</font><font face="book antiqua">Juan Quintanilla</font></div>
<div><font face="book antiqua">UTS - Enterprise Group</font></div>
<div><font face="book antiqua">305-348-6573</font></div>
<div><font face="book antiqua"><a href="mailto:jquin014@fiu.edu">jquin014@fiu.edu</a></font></div>
</div>
<div style="font-family: Times New Roman; color: rgb(0, 0, 0); font-size: 16px;">
<hr tabindex="-1">
<div style="direction: ltr;" id="divRpF112210"><font color="#000000" face="Tahoma" size="2"><b>From:</b> users-bounces@shibboleth.net [users-bounces@shibboleth.net] on behalf of Daniel Fisher [dfisher@vt.edu]<br>
<b>Sent:</b> Monday, February 27, 2012 4:18 PM<br>
<b>To:</b> Shib Users<br>
<b>Subject:</b> Re: Security Advisory 20120227<br>
</font><br>
</div>
<div></div>
<div>DEBUG logs for the edu.vt.middleware.ldap package would also be helpful.<br>
<br>
<div class="gmail_quote">On Mon, Feb 27, 2012 at 4:14 PM, Chad La Joie <span dir="ltr">
&lt;<a href="mailto:lajoie@shibboleth.net" target="_blank">lajoie@shibboleth.net</a>&gt;</span> wrote:<br>
<blockquote class="gmail_quote" style="margin: 0pt 0pt 0pt 0.8ex; border-left: 1px solid rgb(204, 204, 204); padding-left: 1ex;">
Can you provide the cert? &nbsp;Is there a load balancer performing<br>
SSL-offloading involved at all?<br>
<div class="HOEnZb">
<div class="h5"><br>
On 2/27/12 4:01 PM, Juan Quintanilla wrote:<br>
&gt; Hi,<br>
&gt;<br>
&gt; I'm getting a similar error with connection to ldap. &nbsp;We use a wild card cert *.<a href="http://fiu.edu" target="_blank">fiu.edu</a> and the message we receive is:<br>
&gt;<br>
&gt; 15:14:00.487 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109] - unabled to connect to the ldap<br>
&gt; javax.naming.CommunicationException: simple bind failed: <a href="http://fiuldap1.fiu.edu:636" target="_blank">
fiuldap1.fiu.edu:636</a><br>
&gt;<br>
&gt; Caused by: java.security.cert.CertificateException: Hostname '[<a href="http://fiuldap1.fiu.edu" target="_blank">fiuldap1.fiu.edu</a>]' does not match the hostname in the server's certificate<br>
&gt;<br>
&gt; Any ideas?<br>
&gt;<br>
&gt; Thanks!<br>
&gt; ___________________<br>
&gt; Juan Quintanilla<br>
&gt; UTS - Enterprise Group<br>
&gt; <a href="tel:305-348-6573" value="&#43;13053486573" target="_blank">305-348-6573</a><br>
&gt; <a href="mailto:jquin014@fiu.edu" target="_blank">jquin014@fiu.edu</a><br>
&gt; ________________________________________<br>
&gt; From: <a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> [<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a>] on behalf of Mark Cairney [<a href="mailto:mark.cairney@ed.ac.uk" target="_blank">mark.cairney@ed.ac.uk</a>]<br>
&gt; Sent: Monday, February 27, 2012 10:49 AM<br>
&gt; To: Shib Users<br>
&gt; Subject: Re: Security Advisory 20120227<br>
&gt;<br>
&gt; OK I've amended my config to point at one of the individual servers which does match the *.<a href="http://authorise-test.is.ed.ac.uk" target="_blank">authorise-test.is.ed.ac.uk</a> pattern and that seems to be working.<br>
&gt;<br>
&gt; <a href="http://authorise-test.is.ed.ac.uk" target="_blank">authorise-test.is.ed.ac.uk</a> is a round-robin DNS between 2 servers. We do have another identical round-robin DNS which does match the pattern- using this instead would be the simplest solution.<br>
&gt;<br>
&gt; Thanks,<br>
&gt;<br>
&gt; Mark<br>
&gt;<br>
&gt; On 27 Feb 2012, at 15:38, Cantor, Scott wrote:<br>
&gt;<br>
&gt;&gt; On 2/27/12 10:28 AM, &quot;Mark Cairney&quot; &lt;<a href="mailto:mark.cairney@ed.ac.uk" target="_blank">mark.cairney@ed.ac.uk</a>&gt; wrote:<br>
&gt;&gt;&gt;<br>
&gt;&gt;&gt; 15:22:25.776 - ERROR [edu.vt.middleware.ldap.pool.DefaultLdapFactory:109]<br>
&gt;&gt;&gt; - unabled to connect to the ldap<br>
&gt;&gt;&gt; javax.naming.CommunicationException: hostname of the server<br>
&gt;&gt;&gt; '<a href="http://authorise-test.is.ed.ac.uk" target="_blank">authorise-test.is.ed.ac.uk</a>' does not match the hostname in the server's<br>
&gt;&gt;&gt; certificate.<br>
&gt;&gt;<br>
&gt;&gt; That doesn't match the wildcard you have here:<br>
&gt;&gt;<br>
&gt;&gt;&gt; Owner: EMAILADDRESS=<a href="mailto:ext6033@ed.ac.uk" target="_blank">ext6033@ed.ac.uk</a>, CN=*.<a href="http://authorise-test.is.ed.ac.uk" target="_blank">authorise-test.is.ed.ac.uk</a>,<br>
&gt;&gt;&gt; OU=Information Services, O=University of Edinburgh, L=Edinburgh,<br>
&gt;&gt;&gt; ST=Scotland, C=GB<br>
&gt;&gt;<br>
&gt;&gt; That would be a bug to accept it.<br>
&gt;&gt;<br>
&gt;&gt;&gt; Is this expected behaviour and are you aware of any workarounds? This<br>
&gt;&gt;&gt; setup was working fine with Shibboleth 2.3.5..<br>
&gt;&gt;<br>
&gt;&gt; That's because the library in 2.3.5 didn't verify it at all.<br>
&gt;&gt;<br>
&gt;&gt; I believe Daniel allowed for an override of the hostname verification via<br>
&gt;&gt; a custom class. I don't know if there's a class built-in that literally<br>
&gt;&gt; disables the check.<br>
&gt;&gt;<br>
&gt;&gt; -- Scott<br>
&gt;&gt;<br>
&gt;&gt; --<br>
&gt;&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
&gt;&gt;<br>
&gt;<br>
&gt; /*********************************<br>
&gt; Mark Cairney<br>
&gt; ITI UNIX Section<br>
&gt; Information Services<br>
&gt; University of Edinburgh<br>
&gt;<br>
&gt; Tel: 0131 650 6565<br>
&gt; Email: <a href="mailto:mark.cairney@ed.ac.uk" target="_blank">mark.cairney@ed.ac.uk</a><br>
&gt;<br>
&gt; *********************************/<br>
&gt;<br>
&gt;<br>
&gt; --<br>
&gt; The University of Edinburgh is a charitable body, registered in<br>
&gt; Scotland, with registration number SC005336.<br>
&gt;<br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
&gt; --<br>
&gt; To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">
users-unsubscribe@shibboleth.net</a><br>
</div>
</div>
</blockquote>
</div>
<br>
</div>
</div>
</div>
</body>
</html>