<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p><br>
</p>
<div class="moz-cite-prefix">On 3/2/20 7:16 AM, Andrew Vinall wrote:<br>
</div>
<blockquote type="cite"
cite="mid:CAFF683n_jHRz0dL9RvmJoXjLTLbF6BytrQ1MJr2iNigFQnxxPA@mail.gmail.com">
<pre class="moz-quote-pre" wrap="">
I understand Version 4 of Shibboleth will include this update.</pre>
</blockquote>
<p><br>
</p>
<p>Yes, it will ship with 1.2.4. Baring any catastrophic and
unforseen circumstances, OpenSAML 4.0.0 will ship early next week.<br>
</p>
<br>
<blockquote type="cite"
cite="mid:CAFF683n_jHRz0dL9RvmJoXjLTLbF6BytrQ1MJr2iNigFQnxxPA@mail.gmail.com">
<pre class="moz-quote-pre" wrap="">
However, could the 3.x branch be updated to include the backported fix
in cryptacular 1.1.4? Note it is built with JDK7 like its previous
version.
</pre>
</blockquote>
<p><br>
</p>
<p>Given that we've been focused on getting 4.x out the door, we
don't at the moment have any concrete plans for an updated 3.4.x
release. We'll discuss internally.</p>
<p>In the immediate future, from what I see of the changes it's
probably OK to just update your effective dependency to 1.1.4 with
a local Maven override (if using Maven), or just pulling down the
updated jar. The VT authors of that library are on this list and
I'll let them comment on whether they would forsee any problems
with that as a short-term workaround.</p>
<p>I'm sure you can guess that the longer-term answer is going to be
"Update to 4.0".</p>
<p>--Brent<br>
</p>
</body>
</html>