The Incommon Federation wiki has moved.

Please visit the new InCommon Federation Library wiki for updated content. Remember to update your bookmarks.

Click in the link above if you are not automatically redirected in 15 seconds.



You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 13 Next »

This wiki page is a work in progress and will be updated as new information is received and processed.

The Heartbleed Bug

A major new threat is sweeping the Internet. The Heartbleed Bug, announced publicly on April 7, 2014, is a serious vulnerability that affects certain versions of OpenSSL in circulation since 2012.

If you are running SAML software on an affected system, first patch the system and then consider the ramifications of The Heartbleed Bug on your SAML deployment. We can't tell you how to patch your system…at this time all we can do is point you to the official Heartbleed web page linked above.

Implementation-specific Information

Shibboleth: Shibboleth Security Advisory (9 April 2014)

SimpleSAMLphp: https://groups.google.com/forum/#!topic/simplesamlphp/XphXXmVhMVI

Advice to InCommon IdP Operators

Once your system is patched, follow these steps to migrate a new certificate into metadata:

  1. Read the X.509 Certificates in Metadata wiki page
    1. use a long-lived, self-signed certificate
  2. Read the IdP Key Handling wiki page
    1. Handle the private IdP signing key securely!
  3. Read the Certificate Migration wiki page and its child pages
    1. Unless there is evidence that your IdP signing key has been compromised, migrate a new certificate into metadata, do not simply replace the old certificate (which will adversely affect interoperability).
    2. Assuming your SP partners follow InCommon recommendations with respect to Metadata Consumption, wait at least 24 hours for newly updated metadata to propagate throughout the Federation.

Advice to InCommon SP Owners

TBD

Resources

#trackbackRdf ($trackbackUtils.getContentIdentifier($page) $page.title $trackbackUtils.getPingUrl($page))
  • No labels