Shibboleth Security Advisory [23 January 2018]

Cantor, Scott cantor.2 at osu.edu
Thu Jan 25 09:52:11 EST 2018


On 1/25/18, 6:38 AM, "users on behalf of Mark Cairney" <users-bounces at shibboleth.net on behalf of Mark.Cairney at ed.ac.uk> wrote:

> Thanks for your responses. It definitely makes more sense of the
> situation. At the moment we do have some SPs still using SAML1 Attribute
> Queries but this made us identify them and start chasing up the ones we can.

That was my principal goal with the advisory. It's just a chance to raise the fact that legacy behaviors can cause problems by increasing the attack surface.

-- Scott




More information about the users mailing list