<div dir="ltr"><div class="gmail_extra">This is great information, I thank you guys much.</div><div class="gmail_extra"><br></div><div class="gmail_extra">I will work on upgrading Java to 1.7 and possibly OpenSSL and see if that fixes things. We do have a rather old version of OpenSSL on the system, and the related libraries. And, of course, an old version of Java.</div>
<div class="gmail_extra"> <br></div><div class="gmail_extra">I remember when we moved to v2.x we had a big issue with upgrading OpenSSL breaking some service providers, and we had to work with them to get things interoperable. I don't even want to imagine the headaches moving again would create.</div>
<div class="gmail_extra"><br></div><div class="gmail_extra">Chris</div><div class="gmail_extra"><br></div><div class="gmail_extra"> <br></div><div class="gmail_extra"><div class="gmail_quote">On Mon, Jul 29, 2013 at 2:42 PM, Christopher Peters <span dir="ltr"><<a href="mailto:cjpeters@uci.edu" target="_blank">cjpeters@uci.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr">You are correct about it being Tomcat native. That was bad information on my part. When I initially set up the IDP v1 server we used Apache through Tomcat, but when we migrated to 2.1.5 we went native Tomcat and I completely forgot about that change.<div>
<br></div><div>--</div><div><br></div><div>I think the bad cert issue is that we self-sign the cert. It's only used through InCommon and in Metadata, so it doesn't need to go through verification. We are aware it expires in 3 days, and that is why there is a second cert in InCommon Metadata which is soon to replace this one.</div>
</div><div class="gmail_extra"><div><div class="h5"><br><br><div class="gmail_quote">On Mon, Jul 29, 2013 at 2:21 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I would add that if the server's headers are to be believed, that is *not*<br>
Apache, it's Tomcat.<br>
<br>
So yes, I suspect you have an issue with the Java stack here, if that's in<br>
fact the TLS implementation in use.<br>
<br>
Various TLS bugs hit in the middle of the 1.6 JDK cycle, I'd strongly<br>
suggest moving to 1.7, or if absolutely necessary the latest 1.6 and go<br>
from there.<br>
<div><div><br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br><br clear="all"><div><br></div></div></div><div class="im">-- <br><div dir="ltr">
<font face="arial black, sans-serif">Chris Peters</font><br>Middleware Services Developer<br>Office of Information Technology - NSP<br><a href="tel:%28949%29%20824-6845" value="+19498246845" target="_blank">(949) 824-6845</a><br>
<a href="mailto:cjpeters@uci.edu" target="_blank">cjpeters@uci.edu</a><br>
</div>
</div></div>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div dir="ltr">
<font face="arial black, sans-serif">Chris Peters</font><br>Middleware Services Developer<br>Office of Information Technology - NSP<br>(949) 824-6845<br><a href="mailto:cjpeters@uci.edu" target="_blank">cjpeters@uci.edu</a><br>
</div>
</div></div>