Shibboleth SP Service in Java

Cantor, Scott cantor.2 at osu.edu
Wed Jun 4 14:26:36 UTC 2025


> The Java-based shibboleth SP 'service' is intended to replace the
> existing shibd process written in C++. Is there an estimated date
> for the rollout of the Java SP service? 

That's an over-simplification of the changes though it's not entirely inaccurate.

I am hoping to have an alpha of some sort available this calendar year, and shipping something by end of 2026 is the hope, but there's a lot of completely new documentation to do before that can happen and that's probably going to be the bigger hold up. It might be shippable before it's entirely usable and we need to take into account all the issues with the historical approach to documenting things to try and make things better here.

In particular we fully intend to make the agent half much more elementary and lower the barrier for that piece. No SAML, no OpenID, much less XML, as simple as we can make it.

The Java hub OTOH? It's the IdP and more. Same skill set, Java, Spring, XML, SAML, OIDC, all the skills. Nightmare without them as its always been.

I will say very loudly: Apart from the documentation, migration assistance of any sort from me is not going to be provided to non-members of the consortium. Doing this work is a huge cost to the project being underwritten by a ridiculously small percentage of its users. Those members wll get all the help I can give them, and nobody else is getting any from me.

If that's not blunt enough, I give up.

If you're not a member of the consortium, I advise you to pick something else to use in the strongest possible terms unless you have never felt the need for my help to begin with. Freeloading off open source is fine as long as you're capable of supporting yourself. It's inexcusable otherwise.

-- Scott




More information about the users mailing list