cryptacular dependency

Brent Putman putmanb at georgetown.edu
Fri Mar 6 19:59:47 EST 2020


On 3/2/20 7:16 AM, Andrew Vinall wrote:
>
> I understand Version 4 of Shibboleth will include this update.


Yes, it will ship with 1.2.4.  Baring any catastrophic and unforseen 
circumstances, OpenSAML 4.0.0 will ship early next week.


> However, could the 3.x branch be updated to include the backported fix
> in cryptacular 1.1.4?  Note it is built with JDK7 like its previous
> version.


Given that we've been focused on getting 4.x out the door, we don't at 
the moment have any concrete plans for an updated 3.4.x release.  We'll 
discuss internally.

In the immediate future, from what I see of the changes it's probably 
OK to just update your effective dependency to 1.1.4 with a local Maven 
override (if using Maven), or just pulling down the updated jar.  The 
VT authors of that library are on this list and I'll let them comment 
on whether they would forsee any problems with that as a short-term 
workaround.

I'm sure you can guess that the longer-term answer is going to be 
"Update to 4.0".

--Brent

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20200306/e6f0599a/attachment.html>


More information about the dev mailing list