<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
</head>
<body>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">The Shibboleth Project has released version 2.4.0 of the DuoOIDC plugin [1]. We strongly recommend reading the release notes in
 [2] before upgrading. </span></p>
<div style="direction: ltr; font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">
<br>
</div>
<div style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">
All functional changes in version 2.4.0 address issues arising from Duo's updated handling of the auth_time claim, introduced in September 2026. This change has already been rolled out to integrations that are not of the "Shibboleth" type and do not have "shibboleth"
 in their name. With the release of this plugin, we expect Duo's updated behaviour to be rolled out to the remaining Shibboleth integrations.</div>
<div style="direction: ltr; font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">
<br>
</div>
<div style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">
To support this change, version 2.4.0 introduces full support for authentication age, improved forced authentication handling, new authentication-time validation policies, and an updated version of Duo's WebSDK library.</div>
<div style="direction: ltr; font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">
<br>
</div>
<div style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">
The new version of the plugin should resolve compatibility issues for deployments already using Duo's updated behaviour. It also provides additional options for controlling maximum authentication age and validating the authentication time</div>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255);"><br>
</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255);">There are, however,
 some important considerations when upgrading. In previous versions, if an SP requested forced authentication from the IdP, that requirement was not forwarded to Duo. From version 2.4.0, a forced authentication request is forwarded to Duo and, when using Duo's
 updated behaviour, will require the user to reauthenticate, even if they have a valid remembered-device session. This behaviour can be ‘effectively' disabled, if required. </span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; font-size: 16px; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255); text-transform: none;"><br>
</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255);">In addition, there
 are <i>breaking changes</i> to the WebSDK v4 plugin variant for deployments that explicitly override the default set of pinned certificates. Please see the release notes for details on how to migrate your configuration. These changes result from breaking changes
 in the Duo WebSDK API that the plugin needed to accommodate.</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255);"><br>
</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255);">Finally, to simplify
 future maintenance, we are deprecating the Duo WebSDK v4 plugin variant in this release in favour of the Shibboleth Nimbus plugin. Existing deployments will continue to work, but eventually support for the WebSDK v4 variant will be removed.</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; font-size: 16px; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255); text-transform: none;"><br>
</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Atlassian Sans", ui-sans-serif, -apple-system, system-ui, "Segoe UI", Ubuntu, "Helvetica Neue", sans-serif; color: rgb(41, 42, 46); background-color: rgb(255, 255, 255);">Again, please
 read the release notes in [2].</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);"><br>
</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">— Phil Smart, on behalf of the team</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);"><br>
</span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">[1]
</span><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(0, 0, 0);"><a href="https://shibboleth.atlassian.net/wiki/x/twDmUQ" data-outlook-id="415d23b3-d9ff-4509-bf29-853232ee253d" style="margin-top: 0px; margin-bottom: 0px;">https://shibboleth.atlassian.net/wiki/x/twDmUQ</a></span></p>
<p style="line-height: normal; margin: 0px;"><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(25, 25, 25);">[2]
</span><span style="font-family: "Helvetica Neue"; font-size: 16px; color: rgb(0, 0, 0);"><a href="https://shibboleth.atlassian.net/wiki/x/AYCcuQ" data-outlook-id="508abe14-d0c4-4333-9f34-48da0c12d99d" style="margin-top: 0px; margin-bottom: 0px;">https://shibboleth.atlassian.net/wiki/x/AYCcuQ</a></span></p>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="direction: ltr; font-family: Aptos, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<mc type="body"><font size="1"><font face="Corbel"><br>
<p>Jisc is a registered charity (in England and Wales under charity number 1149740; in Scotland under charity number SC053607) and a company limited by guarantee registered in England under company number 05747339, VAT number GB 197 0632 86. Jisc's registered
 office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.<br>
<br>
</p>
<p>For more details on how Jisc handles your data see our privacy notice here: https://www.jisc.ac.uk/website/privacy-notice</p>
</font></font>
</body>
</html>