<html xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Title" content="">
<meta name="Keywords" content="">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Calibri;
        panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0in;
        margin-bottom:.0001pt;
        font-size:11.0pt;
        font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:blue;
        text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
        {mso-style-priority:99;
        color:purple;
        text-decoration:underline;}
span.EmailStyle17
        {mso-style-type:personal-reply;
        font-family:"Calibri",sans-serif;
        color:windowtext;}
span.msoIns
        {mso-style-type:export-only;
        mso-style-name:"";
        text-decoration:underline;
        color:teal;}
.MsoChpDefault
        {mso-style-type:export-only;
        font-size:10.0pt;}
@page WordSection1
        {size:8.5in 11.0in;
        margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
        {page:WordSection1;}
--></style>
</head>
<body bgcolor="white" lang="EN-US" link="blue" vlink="purple">
<div class="WordSection1">
<p class="MsoNormal">Does anyone know the logic behind JVM’s not trusting certs signed by a ‘trusted’ CA?<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div style="border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b><span style="font-size:12.0pt;color:black">From: </span></b><span style="font-size:12.0pt;color:black">users <users-bounces@shibboleth.net> on behalf of "Cantor, Scott" <cantor.2@osu.edu><br>
<b>Reply-To: </b>Shib Users <users@shibboleth.net><br>
<b>Date: </b>Thursday, November 9, 2017 at 2:11 PM<br>
<b>To: </b>Shib Users <users@shibboleth.net><br>
<b>Subject: </b>RE: Shibboleth Identity Provider Security Advisory [4 October 2017]<o:p></o:p></span></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<blockquote style="border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in" id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<p class="MsoNormal">I'm not sure I understand this. The certificates have a validity period and<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">eventually expire. Isn't that to be expected and neither good or bad?<o:p></o:p></p>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Certificates don't need to expire annually, they do because people are hidebound in their thinking. But that's beside the point, as Mike said. If you need/want to trust a CA, then you can trust a CA. Just *trust* it by putting it into the
 configuration instead of assuming the right things will happen by default.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<blockquote style="border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in" id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<p class="MsoNormal">I feel like I don't really have enough context to<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">understand this. If there's IdP documentation that will give a better<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">grasp of this, I'd be happy if you could refer me to it.<o:p></o:p></p>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">We haven't tried to document PKIX for anybody, it's not a Shibboleth thing. What we document is how to configure the trusted certificates, like most server software does, and the affected case is the LDAP DataConnector, so that's the relevant
 documentation. The simplest way to configure it in any recent version is with a simple "trustFile" attribute in the connector element. Put the CA in a file, point trustFile at it, done. It's that simple. That's what the advisory says, or at least it's what
 I thought it said.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<blockquote style="border:none;border-left:solid #B5C4DF 4.5pt;padding:0in 0in 0in 4.0pt;margin-left:3.75pt;margin-right:0in" id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE">
<div>
<p class="MsoNormal">For instance, based on your reply here, it's not clear to me if maintaining the LDAP<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">cert locally will be required going forward regardless of IdP updates as<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">a best practice, or whether 3.3.2 obviates that need in the future. On<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">what basis do we evaluate how we want or need to establish the validation?<o:p></o:p></p>
</div>
</blockquote>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">There's nothing that implies you have to trust the server certificate directly, and there is nothing that will tell you what to do either way, that's a choice. If I could get my LDAP admins to use a long-lived self-signed certificate, I
 would use it directly. But they do not, as yours do not.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">-- Scott<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">-- <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
</div>
</body>
</html>