<div dir="ltr">T<font color="#000000">he other day, I read that OpenSAML is not supported for use as an independent library [1]:</font><div><font color="#000000"><br></font></div><div><font color="#000000">> <span style="font-family:Verdana,Geneva,Helvetica,Arial,sans-serif">We don't formally support OpenSAML for use as an independent library, only as part of our IdP product.</span></font></div><div><font color="#000000"><br></font><div><font color="#000000">Spring Security's SAML 2.0 Service Provider support uses OpenSAML 3 [2] as an independent library. I'm currently in the process of adding OpenSAML 4 to that support [3]. Is this not recommended?</font></div><div><font color="#000000"><br></font></div><div><font color="#000000">I got confused since the documentation has a section titled "Projects Using OpenSAML" [4] that lists several projects that use OpenSAML as an independent library.</font></div><div><font color="#000000"><br></font></div><div><font color="#000000">That same page also says:</font></div><div><font color="#000000"><br></font></div><div><font color="#000000">> <span style="font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif">The </span>current stable release<span style="font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif"> </span><span style="font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif">of the Java library is the latest version available from our Nexus </span>repository ...<span style="font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif"> in most cases you can assume that all prior releases are unsupported.</span></font></div><div><span style="font-family:-apple-system,BlinkMacSystemFont,"Segoe UI",Roboto,Oxygen,Ubuntu,"Fira Sans","Droid Sans","Helvetica Neue",sans-serif"><font color="#000000"><br></font></span></div><div><font face="-apple-system, BlinkMacSystemFont, Segoe UI, Roboto, Oxygen, Ubuntu, Fira Sans, Droid Sans, Helvetica Neue, sans-serif" color="#000000">which seems to imply some form of support for the current stable release. </font></div><div><font face="-apple-system, BlinkMacSystemFont, Segoe UI, Roboto, Oxygen, Ubuntu, Fira Sans, Droid Sans, Helvetica Neue, sans-serif" color="#000000"><br></font></div><div><span style="color:rgb(0,0,0)">Can you clarify what is supported and what isn't? If it's not recommended for Spring Security to base its Service Provider support on OpenSAML, do you have any alternatives you would recommend?</span></div><div><font color="#000000"><br></font></div><div><font color="#000000">Thanks!</font></div><div><font color="#000000"><br clear="all"></font><div><font color="#000000">[1] - <a href="https://shibboleth.1660669.n2.nabble.com/Security-issue-on-Java-OpenSaml-Library-td7646686.html" target="_blank">https://shibboleth.1660669.n2.nabble.com/Security-issue-on-Java-OpenSaml-Library-td7646686.html</a></font></div><div><font color="#000000">[2] - </font><a href="https://github.com/spring-projects/spring-security/blob/master/saml2/saml2-service-provider/spring-security-saml2-service-provider.gradle" target="_blank">https://github.com/spring-projects/spring-security/blob/master/saml2/saml2-service-provider/spring-security-saml2-service-provider.gradle</a></div><div><font color="#000000">[3] - </font><a href="https://github.com/spring-projects/spring-security/issues/9095" target="_blank">https://github.com/spring-projects/spring-security/issues/9095</a></div><div><font color="#000000">[4] - <a href="https://wiki.shibboleth.net/confluence/display/OS30/Home#Home-ProjectsUsingOpenSAML" target="_blank">https://wiki.shibboleth.net/confluence/display/OS30/Home#Home-ProjectsUsingOpenSAML</a><br></font></div></div></div></div>