Shibboleth Identity Provider Security Advisory [13 May 2026]

Scott Cantor scott at restingparrotsoftware.com
Thu May 14 17:15:26 UTC 2026


> AFAIU Scott the Shibboleth MDA should have functionality to
> canonicalise those prefixes?

It can. I don't know that it *does* automatically or anything, the MDA is a pipeline management tool for defining stages of processing and has a lot of built-in stages. I imagine one of them probably normalizes namespace declarations.

Regardless, the point is that the only thing we can control is what we support, and we made sure that the supported version's changes were not going to be incompatible with those metadata feeds while still addressing the security report. That's all we can do.

Nothing else anyone is running is going to suddenly break unless people choose to apply changes and break things. Not unless Java decides to default those options to much lower numbers than they have to this point.

I will change the advisory to point out that we have no control over what settings happen to be "safe" to use in a particular version that isn't the one we support.

-- Scott



More information about the users mailing list