2024-02-16

Shibboleth Developer's Meeting, 2024-02-16

Call Administrivia

09:00 Central US / 10:00 Eastern US / 15:00 UK / 17:00 FI

Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 2024-03-01 Any reason to deviate from this?

60 to 90 minute call window.

Call Details

This week's call will use the Zoom system at GU, see ZoomGU for access info.

AGENDA

  • Rod: IDP-2242 Can/Should we stop using “Unsupported” and rely instead on SECADV/OutOfDate/Current

  • 5.1 freeze schedule

    • Feature freeze on 2/26, code freeze 3/4 and release that week if possible

  • Santuario (C++) future

    • Will make a proposal for a cut down V3 either at Apache if accepted, or we close it down, and fork if not (at which point it’s optional for us to do if we want).

Attendees:

Brent

 

Daniel

 

Henri

Ian

 

John

 

Marvin

 

Phil

  • RP developments

  • WebAuthn developments:

    • JWEBAUTHN-2: Add the WebAuthn plugin to JenkinsClosed Missing 1 key for cose-java. It looks like Emil has eliminated that dependency from the Yubico libraries, and will be releasing a patch release (2.5.1) very soon. When we grab that, we will not need the key.

    • Lots of cleanups.

    • A decent amount of work on the registration process.

      • Username and password authentication to first register a WebAuthn credential, but WebAuthn flow is required once you have one.

        • Requires username collection as a first step in the registration flow.

    • Adding attestation support even if not used initially.

       

Rod

 

Scott

Tom

  • OIDC tests : looking for example / test flows (as discussed on Slack, thank you)

  • nit : maybe add link to source on wiki pages for IdP plugins

Other