...
Known Issues
None at this time.
3.5.0 (October 16, 2024)
Jira Legacy | ||||||||
---|---|---|---|---|---|---|---|---|
|
This is a small update to address a few bugs, update a number of libraries, and implement a correction to the default signing algorithm used when issuing signed requests via the SAML POST binding. This was inadvertently still defaulting to RSA-SHA1 and should have been using RSA-SHA256. There is the unlikely possibility of this causing interoperability issues with badly out of date Identity Providers, so is another reason for releasing it as a minor update. Those impacted are free to override the signing algorithm as documented.
This release is accompanied by an update to Xerces-C V3.3.0, OpenSAML V3.3.0, and a new fork of the now-retired Santuatio XML-Security library which has been maintained by the project for many years and is now a local fork of that code with large portions removed, released as V3.0.0.
The Windows installation package also includes the very latest releases of libcurl and OpenSSL to address the non-impacting CVEs that have been flagged by security scanners.
3.4.1.5 (April 29, 2024)
A new version of the Windows installer was released to address an installer issue with localized versions of Windows. The software itself is unchanged.
...