<div dir="ltr"><div><div><div>Hello,<br></div><div>     I am using shibboleth 2.5.0 version,ExternalIdp and a custom Service Provider(Not Shibboleth SP) Recently, there were OpenSSL issues submitted by openSSL group(refer:<a href="https://www.openssl.org/news/secadv_20150319.txt">openssl_issues</a>).I am having few questions on OpenSSL lib on shibboleth<br></div><div>- Is Shibboleth IDP using any openSSL libraries?<br></div><div>- If I upgrade my OpenSSL version, certificate on my tomcat server, Is it required to upgrade the shibboelth IDP?<br></div><div>- Can I directly update the public key at the &#39;KeyDescriptor&gt;ds:X509Certificate&#39; element on idp-metadata.xml? Will it effect any existing functionality?<br></div><br><br><br><br><br><br></div>Thanks &amp; Regards,<br></div>Sarath U<br></div>