Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Known Issues

None at this time.

3.5.0 (October 16, 2024)

Jira Legacy
serverSystem Jira
jqlQueryfilter=10069
counttrue
serverIdf52c7d31-6eab-3f0e-93c3-231b5754d506

This is a small update to address a few bugs, update a number of libraries, and implement a correction to the default signing algorithm used when issuing signed requests via the SAML POST binding. This was inadvertently still defaulting to RSA-SHA1 and should have been using RSA-SHA256. There is the unlikely possibility of this causing interoperability issues with badly out of date Identity Providers, so is another reason for releasing it as a minor update. Those impacted are free to override the signing algorithm as documented.

This release is accompanied by an update to Xerces-C V3.3.0, OpenSAML V3.3.0, and a new fork of the now-retired Santuatio XML-Security library which has been maintained by the project for many years and is now a local fork of that code with large portions removed, released as V3.0.0.

The Windows installation package also includes the very latest releases of libcurl and OpenSSL to address the non-impacting CVEs that have been flagged by security scanners.

3.4.1.5 (April 29, 2024)

A new version of the Windows installer was released to address an installer issue with localized versions of Windows. The software itself is unchanged.

...