How can we help on https://git.shibboleth.net/view/?p=java-sp-server.git ?

Jason Pyeron jpyeron at pdinc.us
Fri May 27 17:52:38 UTC 2022


> -----Original Message-----
> From: users <users-bounces at shibboleth.net> On Behalf Of Cantor, Scott via users
> Sent: Monday, May 23, 2022 1:30 PM
> To: Shib Users <users at shibboleth.net>
> Cc: Cantor, Scott <cantor.2 at osu.edu>
> Subject: Re: How can we help on https://git.shibboleth.net/view/?p=java-sp-server.git ?
> 
> This discussion should be on the dev list, but it is perhaps unlikely that your goal is related to the
> near term goals of this work.
> 
> There are no plans any time soon (like within some years) to produce an SP that supports Java
> applications natively. That's not what that project is. And I suspect that's what you're probably
> trying to find. This isn't a Java SP, it's an implementation of a processing server for the currently

Would not complain if it existed :)

> supported SP agents to get rid of the C++ code related to SAML and XML parsing, which is not
> sustainable code. It's shibd in Java, for lack of a more precise label. That's what the "server" in
> the name is referring to.
> 
> An SP that supports Apache and IIS supports almost everything in some sense. An SP that supports Java
> supports only Java. That continues to dictate priorities.
> 
> As the work develops, there will be public documentation for an API that hopefully will allow
> additional agents to be developed with hopefully a reasonably small code footprint, and we're more
> than happy to see others doing them.
> 
> I guess to answer the question, at this stage, the most anybody could do is join dev calls and if they
> have thoughts on the redesign [1] or what this server can be for other use cases, share them there or
> on the dev list.
> 

Happy to help, including some of my resources. Will continue to monitor.

Regarding [1] and security thoughts

1. there is no compelling reason today to not use mutual (2-way) authenticated TLS as a transport.
2. when possible messages/payloads should maintain nonrepudiation (e.g. a signature wrapper)

> -- Scott
> 
> [1] https://wiki.shibboleth.net/confluence/display/SP3/DesignNotes
> 
> --
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



--
Jason Pyeron  | Architect
PD Inc        | Certified SBA 8(a)
10 w 24th St  | Certified SBA HUBZone
Baltimore, MD | CAGE Code: 1WVR6
 
.mil: jason.j.pyeron.ctr at mail.mil
.com: jpyeron at pdinc.us
tel : 202-741-9397





More information about the dev mailing list