Shibboleth Service Provider Security Advisory [17 March 2021] - backporting

wferi at niif.hu wferi at niif.hu
Wed Mar 17 16:13:40 GMT 2021


"Cantor, Scott" <cantor.2 at osu.edu> writes:

> The cpp-sp git commit containing the fix for this issue is
> d1dbebfadc1bdb824fea63843c4c38fa69e54379

Hi Scott,

When backporting the above commit to 3.0.4 (to create a Debian stable
update) schemas/shibboleth-3.0-native-sp-config.xsd gave conflicts which
I'm not entirely sure about.  Is it okay to straightforwardly add

+    <attribute name="externalParameters" type="boolean" />

while leaving the version attribute of the <schema> element at 3.0?
When is this schema file used?
The changes to the 4 .cpp files applied cleanly, I think that's all
there is to do, right?
-- 
Thanks,
Feri



More information about the Pkg-shibboleth-devel mailing list