By: Joshua McMillen Account Admin 04 May 2016 at 2:04 p.m. CDT

3 Responses
Joshua McMillen gravatar
We recently received this attached advisory and we were wondering if you knew if this affected the GLUU implementation of shibboleth or not. Thank You, Josh

By Mohib Zico staff 04 May 2016 at 2:15 p.m. CDT

Mohib Zico gravatar
This is about Shibboleth SP, Gluu Server acts as Shibboleth IDP

By Joshua McMillen Account Admin 05 May 2016 at 7:37 a.m. CDT

Joshua McMillen gravatar
And that was my understanding, but I was told to ask the question in case any portion of the gluu was protected by a shibboleth sp, and so here we are. I am closing this ticket. Thank you, Josh

By Mohib Zico staff 05 May 2016 at 9:05 a.m. CDT

Mohib Zico gravatar
Yep. There is one shibboleth sp piece inside Gluu Server but that piece can't be contacted from outside of the VM. It is basically used by Shibboleth IDP itself. Then again, here is the status of that 'shibboleth2.xml' file; we don't have any 'ignoreCase' code there. Feel free to test please! ``` -bash-4.1$ cat shibboleth2.xml | grep -i 'ignoreCase' -bash-4.1$ pwd /etc/shibboleth -bash-4.1$ ```