<div dir="ltr"><div><div>Hello Scott,<br><br></div>I noticed you removed the endorsed/ directory instructions recently. Should we remove those libs from the tomcat endorsed directory as well or we can just leave them there?<br><br></div>Kind regards,<br>Athanasios<br><br></div><div class="gmail_extra"><br><div class="gmail_quote">On Tue, Nov 4, 2014 at 4:02 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">The Shibboleth Project has released a patch update, V2.4.3, of the<br>
Identity Provider software, along with an update of the OpenSAML library,<br>
2.6.4.<br>
<br>
This release primarily addresses the security advisory just announced<br>
addressing a denial of service vulnerability in the Xerces XML parser, and<br>
fixes a bug in the code around scripted attributes when Java 8 is used.<br>
<br>
You can download the new release from the usual location [1] and we are in<br>
the process of updating documentation now.<br>
<br>
-- Scott<br>
<br>
[1] <a href="http://shibboleth.net/downloads/identity-provider/latest/" target="_blank">http://shibboleth.net/downloads/identity-provider/latest/</a><br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:announce-unsubscribe@shibboleth.net">announce-unsubscribe@shibboleth.net</a><br>
</blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature">Athanasios Douitsis<br><br><br></div>
</div>