Page MenuHomePhabricator

Update CAS to 6.2
Open, MediumPublic

Description

We should upgrade CAS to the latest upstream branch (6.2, so 6.2.4).

This also fixes a security issue in gauth (CVE-2020-27178, https://apereo.github.io/2020/10/14/gauthvuln/), we doesn't affect us, since we don't use the affected functionality.

Event Timeline

Change 634907 had a related patch set uploaded (by Muehlenhoff; owner: Muehlenhoff):
[operations/software/cas-overlay-template@master] Bump to 6.2.4

https://gerrit.wikimedia.org/r/634907

Marostegui triaged this task as Medium priority.Oct 19 2020, 10:33 AM

Change 634907 merged by Muehlenhoff:
[operations/software/cas-overlay-template@master] Bump to 6.2.4

https://gerrit.wikimedia.org/r/634907

Mentioned in SAL (#wikimedia-operations) [2020-10-26T13:48:55Z] <moritzm> imported cas 6.2.4-1 to apt.wikimedia.org T265857

Change 639098 had a related patch set uploaded (by Jbond; owner: John Bond):
[operations/software/cas-overlay-template@master] cas: gradle seems to have switch to using implmentation for dependencies

https://gerrit.wikimedia.org/r/639098

Change 639098 merged by Jbond:
[operations/software/cas-overlay-template@master] cas: gradle seems to have switch to using implmentation for dependencies

https://gerrit.wikimedia.org/r/639098

I was looking at prometheus jobs down alert today and idp shows up there, I'm assuming because the prometheus endpoint has been removed in Ia4b089af. Please remove the IDP prometheus job as well, thanks!

Change 640086 had a related patch set uploaded (by Muehlenhoff; owner: Muehlenhoff):
[operations/puppet@production] Disable apereo_cas_jobs in Prometheus scraping

https://gerrit.wikimedia.org/r/640086

Change 640086 merged by Muehlenhoff:
[operations/puppet@production] Disable apereo_cas_jobs in Prometheus scraping

https://gerrit.wikimedia.org/r/640086

Change 641416 had a related patch set uploaded (by Muehlenhoff; owner: Muehlenhoff):
[operations/dns@master] Point idp CNAME to idp2001

https://gerrit.wikimedia.org/r/641416

Change 641416 merged by Jbond:
[operations/dns@master] Point idp CNAME to idp2001

https://gerrit.wikimedia.org/r/641416