<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Two comments:<br>
1. I figured why my updates were failing for the Shibboleth SP we have on AWS.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Our SP servers run on an <i>Amazon Linux 2</i> kernel that behaves as a CentOS 7 kernel.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
The last time I ran a full update of the server infrastructure was 2019.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Unfortunately, the cert bundles under /etc/pki/tls had expired.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Updating those cert bundles corrected the problem.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
2. It appears someone fixed the browser-related certificate error I was experiencing when trying to access
<a href="https://www.shibboleth.net" id="LPlnk669329">https://www.shibboleth.net</a>.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Whoever runs <a href="http://www.shibboleth.net" id="LPlnkOWALinkPreview">www.shibboleth.net</a> seems to have fixed the certificates that caused my zscaler InternetSecurity system to bitterly complain when I would try to access the Shibboleth Consortium. 
 Thanks to whoever made that change!!!  Greatly appreciated.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Cheers,</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Paul</div>
<div class="_Entity _EType_OWALinkPreview _EId_OWALinkPreview _EReadonly_1">
<div id="LPBorder_GTaHR0cDovL3d3dy5zaGliYm9sZXRoLm5ldC8." class="LPBorder612833" style="width: 100%; margin-top: 16px; margin-bottom: 16px; position: relative; max-width: 800px; min-width: 424px;">
<table id="LPContainer612833" role="presentation" style="padding: 12px 36px 12px 12px; width: 100%; border-width: 1px; border-style: solid; border-color: rgb(200, 200, 200); border-radius: 2px;">
<tbody>
<tr valign="top" style="border-spacing: 0px;">
<td>
<div id="LPImageContainer612833" style="position: relative; margin-right: 12px; height: 126px; overflow: hidden; width: 240px;">
<a target="_blank" id="LPImageAnchor612833" href="http://www.shibboleth.net/"><img id="LPThumbnailImageId612833" alt="" height="126" style="display: block;" width="240" src="https://www.shibboleth.net/wp-content/uploads/2020/11/shibboleth-share.jpg"></a></div>
</td>
<td style="width: 100%;">
<div id="LPTitle612833" style="font-size: 21px; font-weight: 300; margin-right: 8px; font-family: wf_segoe-ui_light, "Segoe UI Light", "Segoe WP Light", "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif; margin-bottom: 12px;">
<a target="_blank" id="LPUrlAnchor612833" href="http://www.shibboleth.net/" style="text-decoration: none; color: var(--themePrimary);">Shibboleth Consortium - Shaping the future of Shibboleth Software</a></div>
<div id="LPDescription612833" style="font-size: 14px; max-height: 100px; color: rgb(102, 102, 102); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif; margin-bottom: 12px; margin-right: 8px; overflow: hidden;">
The Shibboleth Consortium is committed to ensuring our team of dedicated developers are able to keep the software freely available to users.</div>
<div id="LPMetadata612833" style="font-size: 14px; font-weight: 400; color: rgb(166, 166, 166); font-family: wf_segoe-ui_normal, "Segoe UI", "Segoe WP", Tahoma, Arial, sans-serif;">
www.shibboleth.net</div>
</td>
</tr>
</tbody>
</table>
<div id="LPCloseButtonContainer612833" class="_2M3vYXiVaXB9t5mk-HJrJj" tabindex="0" title="Remove link preview" role="button">
<i data-icon-name="Cancel" aria-hidden="true" id="LPCloseButton612833" class="X4fFibeUI1qc3DQiCmjWf root-227"></i></div>
<div id="LPCloseButtonContainer612833" class="_2M3vYXiVaXB9t5mk-HJrJj" tabindex="0" title="Remove link preview" role="button">
<i data-icon-name="Cancel" aria-hidden="true" id="LPCloseButton612833" class="X4fFibeUI1qc3DQiCmjWf root-227"></i></div>
</div>
</div>
<br>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of mat houser <mhouser@uwm.edu><br>
<b>Sent:</b> Friday, February 25, 2022 12:26 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net>; users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Bad server certificate trying to get to the top-level https://shibboleth.net from AWS or a zscaler address</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">FWIW I started noticing that a bunch of certs issued by Let's Encrypt<br>
are being reported as expired by curl and openssl s_client on some<br>
systems. The affected systems all appear to have been running for<br>
quite some time without getting updated.<br>
<br>
RHEL6 (eol Dec 2020 iirc) shows expired as does a "managed" Mac that<br>
hasn't been updated in a very long time. Anything that's been kept up to<br>
date does not show those certificates as expired. My suspicion is that<br>
anything that hasn't been updated since the Let's Encrypt root cert<br>
expired back in September might be relying on an obsolete CA bundle or<br>
something, and updating the client OS should probably fix it.<br>
<br>
-- <br>
-------------<br>
mat:houser<br>
mhouser@uwm.edu<br>
uwm:uits:iam-support<br>
-------------<br>
<br>
On Fri, 25 Feb 2022, Peter Schober wrote:<br>
<br>
* Cantor, Scott <cantor.2@osu.edu> [2022-02-25 14:35]:<br>
> Even the cert on <a href="https://urldefense.com/v3/__http://www.shibboleth.net__;!!NknhfzgzgQ!jCREGPJzdADDzHRBImrYjWkvWlKRotp9IoTp-Aa0pLabXG3hQ870-H9QQWcG5nknRv4$">
https://urldefense.com/v3/__http://www.shibboleth.net__;!!NknhfzgzgQ!jCREGPJzdADDzHRBImrYjWkvWlKRotp9IoTp-Aa0pLabXG3hQ870-H9QQWcG5nknRv4$</a> , which is not run by us, is still valid.<br>
<br>
That server has a misconfigured cert chain, though, by producing only<br>
the leaf/server certificate but not the intermediate one.<br>
(SSL certificate problem: unable to get local issuer certificate)<br>
<br>
But while JISC should fix that ASAP[1] that wouldn't cause an expired<br>
certificate error either, of course...<br>
<br>
-peter<br>
<br>
[1] The reason this hasn't caused sufficient problems in practice is<br>
that browsers cache intermediates, it seems, and that most browsers<br>
will know the (missing) intermediate from other, correctly configured,<br>
servers. It's still wrong, of course.<br>
-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!NknhfzgzgQ!jCREGPJzdADDzHRBImrYjWkvWlKRotp9IoTp-Aa0pLabXG3hQ870-H9QQWcGcv_LM0s$">
https://urldefense.com/v3/__https://shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!NknhfzgzgQ!jCREGPJzdADDzHRBImrYjWkvWlKRotp9IoTp-Aa0pLabXG3hQ870-H9QQWcGcv_LM0s$</a>
<br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
<div>
<p style="font-size:8pt; line-height:8pt; font-family: 'Calibri',serif; color:#696969">
Confidentiality note: This e-mail may contain confidential information from Clarivate. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this e-mail is strictly prohibited. If you have received
 this e-mail in error, please delete this e-mail and notify the sender immediately.
</p>
</div>
</body>
</html>