Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 17 Next »

Shibboleth Developer's Meeting, 2019-08-02

Call Administrivia

09:00 Central US / 10:00 Eastern US / 15:00 UK / 17:00 FI

Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 16th. Any reason to deviate from this?

60 to 90 minute call window.


Call Details

This week's call will use the Zoom system at GU, see ZoomGU for access info.


AGENDA

  • IDP-1472 - Getting issue details... STATUS  (Rod)
    • Do we have a definitive list (of characters to bar)
    • What to do about Transcoders (is their work to map bad characters)?
  • IDP-1181 - Getting issue details... STATUS  (Rod)
    • See my summary 
    • Where do we want fast fail to end up?
  • Jetty version.  This is still pinned to 9.2


Brent


Daniel


Henri


Ian

  • OSJ-279 - Getting issue details... STATUS
  • JSPT-91 - Getting issue details... STATUS
  • INFRA-223 - Getting issue details... STATUS
  • FYI: CentOS 8 team now report that they are "working" on RC.


Marvin


Phil

  • 10 days off, no progress.
  • Will continue or start
    • https://issues.shibboleth.net/jira/projects/IDP/issues/IDP-1191 : Deeper investigation and testing of the flow execution listener CSRF protection
    • IDP-1476 : add a SameSite servlet filter to add SameSite=none cookie attribute to the IdP session cookie.
    • Add a test that checks the/a container does not allow session id’s in URLs when configured not to - as is the case in Jetty < 9.4.12.v20180830.


Rod

  • Do we care about reloading metadata providers  at depth > 1 (this thread)
  • Installation
    • Technologies?  Our requirements are fixed, but there must be a better least worst technology
    • Greater user control.


Scott


Tom

  • AWS work continues
    • worked through : Java updates, resizing storage, OS updates
    • working on integration-tests multi-config jobs (Jetty 9.3/9.4 for IdPV3/V4)
    • leaning towards one-Java-per-OS in AWS
      • just easier to update on Linux
        • i.e. run Amazon Linux rather than install Coretto on RedHat/CentOS
      • Windows ?
    • rationalize Jenkins with Java Distributions
  • AWS TODO :
    • IAM setup 
    • scripting

Other




  • No labels