2023-01-06

Shibboleth Developer's Meeting, 2022-01-06

Call Administrivia

09:00 Central US / 10:00ย Eastern US /ย 15:00ย UK / 17:00 FI

Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 2023-01-20.ย Any reason to deviate from this?

60 to 90 minute call window.

Call Details

This week's call will use theย Zoomย system at GU, seeย ZoomGUย for access info.

AGENDA

Add items for discussion here

Attendees:

Brent

  • Out for last 2.5 weeks.

  • Will begin impl of proposed OpenSAML decryption remediation immediately. Expect to be done by mid-next week at latest.

Daniel

  • Nothing today.

Henri

Ian

John

ย 

Marvin

ย 

Phil

ย 

Rod

Scott

  • Nothing over break

  • Worked through some small 4.3 backlog this week and started testing snapshot at OSU, expect to complete bulk of testing this week

  • Did initial analysis of SP exposure to the XML Encryption issue through experimental testing and analysis of xml-sec-c code

    • SP does honor CipherReference as expected

    • SP would attempt XSLT and XPath transforms if Santuario were built againt Xalan, though I obviously do not in my packages

      • Even so, it doesnโ€™t follow that the issues in Java could apply, but I donโ€™t know how generic the โ€œexternal calloutโ€ hook in XSLT is

    • SP seems NOT to be able to resolve remote references in the encryption code, and my belief from code review is that by some weird coincidence, Santuario โ€œaccidentallyโ€ doesnโ€™t install the default URL resolver code into the Cipher objects the way it does for Signature objects. I donโ€™t know why and am not 100% sure yet that Iโ€™m correct, need to debug it.

      • I can trigger a particular exception message failing to deref the URI that appears to be a product of the resolver being null.

Tom

  • Some module and plugin tests

    • verify that the IdP starts with all modules enabled and plugins installed

Other

ย