Santuario patch coming shortly

Etienne Dysli Metref etienne.dysli-metref at switch.ch
Thu Aug 2 10:05:43 BST 2018


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On 01/08/18 15:35, Cantor, Scott wrote:
> This is easily backportable to the older Santuario versions used
> in Debian now for maintenance purposes but I don't have any plans
> right now to do a 2.x SP patch for Windows, I just don't think the
> 3.0 upgrade has been a problem since I got the initial patches done
> so this is the perfect bug to force people to update if they want
> the fix.

I've tried cherry picking commits [4a68383] and [6cbf18f] on top of
1.7.3 but 4a68383 doesn't apply cleanly and the interface change of
XSECKeyInfoResolverDefault::resolveKey causes further compile errors
down the chain (even propagating this change to XSECKeyInfoResolver
and InteropResolver also causes errors)... I'm not used to C++ so I
don't feel comfortable messing around with the code more than that.

Ferenc, do you intend to make a security update of 1.7.3-4 for stretch?

  Etienne


[4a68383] https://git.apache.org/santuario-cpp.git commit
4a68383b73e4e0108f92418ad8d312ca98800934
  git-svn-id:
https://svn.apache.org/repos/asf/santuario/xml-security-cpp/trunk@183723
6
13f79535-47bb-0310-9956-ffa450edef68

[6cbf18f] https://git.apache.org/santuario-cpp.git commit
6cbf18f79a97c8a5550d9dbb9f297de72765eac7
  git-svn-id:
https://svn.apache.org/repos/asf/santuario/xml-security-cpp/trunk@183724
0
13f79535-47bb-0310-9956-ffa450edef68
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJbYslbAAoJEEyTGWk1pDm1YRsQAKwmB0s13o4MP+MboBpAfHhs
my4dwS6galL1upCs2sF8Xc04K1LDaVfL9BViwQY/o1xoYslVD43iQmldtU/03cK+
+mjH+wZRomu48Olwn4+vVvPPJifIT1t7o5yN0s1kAkRy9ZeTWo4IoKYUZzjNt/13
zt8ob+cH7gPUe7m11F8ObIG+vfWTyWHB1AtX/YkpOO96GDfwOM9eW1KQw1GrWpXj
howH/WEOX3tvPQxNWgtbS+egRMc2FBwiMDnNe5lR4dAYKrW/Mrqa6gBK8pbEKIXt
K/EL470dLzq/lbJkQwkuVL5YnBcv3qRPU24jIqu6powwv6zl1hgo1L7isCdylKIp
sTkaZUZNXatkT5/Nt30D8D86NC+rclBy2hSUbidHG3MHKLhvvRUIjWzEE/8m2zl7
BVPuZeqwtUoJlir2T3zC1knxAuOzY1w0SZbWE2cTNEX8EULTO6Hbq75Q8qKcc6xo
qJR3CoMBATLBfSronH2ulyHA9bbPxkjj7+li3cMRRq+s3l7q28NOQVW9mI42oMSC
EwVRJ2q6/PZkZUUf2L6NaEHB6duVBB8+OOErfBDDz3JT4jtQZAwOiGLKpVrqJJHr
FFGK0ciVvInqVLYN4DDTEOBRcd2f6WztkTkXnzEJLA+IihAG3h6QNwjVpm9c3bqN
46d/0LZY2/cPPzJE/WOz
=Sipv
-----END PGP SIGNATURE-----



More information about the Pkg-shibboleth-devel mailing list