Shibboleth Service Provider Security Advisory [2018-01-12]

Cantor, Scott cantor.2 at osu.edu
Tue Jan 16 16:36:58 EST 2018


> question from our security officer -- has the SHib project considered
> getting CVE numbers for these advisories ?

We get them from Debian for the SP because they find it useful and I'm happy to accomodate them for all the work they do; we don't for the IdP as I find them worse than useless and am sick and tired of being spammed by the supposed security lists for reporting vulnerabilities.

-- Scott



More information about the users mailing list