DuoOIDC Plugin v2.4.0 now available
Philip Smart
Philip.Smart at jisc.ac.uk
Wed Sep 23 17:04:36 UTC 2026
The Shibboleth Project has released version 2.4.0 of the DuoOIDC plugin [1]. We strongly recommend reading the release notes in [2] before upgrading.
All functional changes in version 2.4.0 address issues arising from Duo's updated handling of the auth_time claim, introduced in September 2026. This change has already been rolled out to integrations that are not of the "Shibboleth" type and do not have "shibboleth" in their name. With the release of this plugin, we expect Duo's updated behaviour to be rolled out to the remaining Shibboleth integrations.
To support this change, version 2.4.0 introduces full support for authentication age, improved forced authentication handling, new authentication-time validation policies, and an updated version of Duo's WebSDK library.
The new version of the plugin should resolve compatibility issues for deployments already using Duo's updated behaviour. It also provides additional options for controlling maximum authentication age and validating the authentication time
There are, however, some important considerations when upgrading. In previous versions, if an SP requested forced authentication from the IdP, that requirement was not forwarded to Duo. From version 2.4.0, a forced authentication request is forwarded to Duo and, when using Duo's updated behaviour, will require the user to reauthenticate, even if they have a valid remembered-device session. This behaviour can be ‘effectively' disabled, if required.
In addition, there are breaking changes to the WebSDK v4 plugin variant for deployments that explicitly override the default set of pinned certificates. Please see the release notes for details on how to migrate your configuration. These changes result from breaking changes in the Duo WebSDK API that the plugin needed to accommodate.
Finally, to simplify future maintenance, we are deprecating the Duo WebSDK v4 plugin variant in this release in favour of the Shibboleth Nimbus plugin. Existing deployments will continue to work, but eventually support for the WebSDK v4 variant will be removed.
Again, please read the release notes in [2].
— Phil Smart, on behalf of the team
[1] https://shibboleth.atlassian.net/wiki/x/twDmUQ
[2] https://shibboleth.atlassian.net/wiki/x/AYCcuQ
Jisc is a registered charity (in England and Wales under charity number 1149740; in Scotland under charity number SC053607) and a company limited by guarantee registered in England under company number 05747339, VAT number GB 197 0632 86. Jisc's registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
For more details on how Jisc handles your data see our privacy notice here: https://www.jisc.ac.uk/website/privacy-notice
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/announce/attachments/20260923/0b2d767f/attachment.htm>
More information about the announce
mailing list