Page tree
Skip to end of metadata
Go to start of metadata

Shibboleth Developer's Meeting, 2017-06-02

Call Administrivia

10:00 Central US / 11:00 Eastern US / 16:00 UK

Calls are normally the 1st and 3rd Fridays of each month. Next call would be Friday 2017-06-02. Any reason to deviate from this?

60 to 90 minute call window.

Call Details

This week's call will use the Zoom system at GU, see ZoomGU for access info.


  1. Bouncy Castle CVEs
  2. Any comments on straw man opensaml-bom module?



  • JPAR-94 - Getting issue details... STATUS
  • Researching/evaluating Nimbus OIDC/OAuth2 library, which I missed before.  Previously I only reviewed the Nimbus JOSE library.
  • Will soon backfill changes for metrics/status page for recent metadata resolver enhancements



  • REFEDS talk:
    • under-rehearsed, don't watch it
    • far more people using MFA than I thought, even in Europe
      • early clarification of which parts of current MFA solution will be deprecated will be appreciated
    • far more people (like, 25 or 30) than I expected put their hands up as MDA users



  • Mostly SP
  • IDP-1042 - Getting issue details... STATUS


  • IDP-1170 - Getting issue details... STATUS
    • XML schema TBD
    • HttpClient docs, stil making some tweaks to fill in gaps, e.g. we don't have a way to do pre-emptive basic-auth
  • Will work on helper code to handle deprecation warnings and then get focus back on SP


  • jetty-base : download vs unpack > both
    • just a handful of files
    • download :
      • mkdir modules
        wget some-versioned-path -O modules/idp.module
        java -jar path-to-jetty-start.jar --create-startd --add-to-start=idp
      • more suitable for deployers
    • unpack :
      • wget some-versioned-path/|.tgz
        unpack ...
      • more suitable for integration tests and Windows installer
      • code changes to change from unpack to download, so do both
    • both
      • add [files] to idp.module as well as dependent modules like idp-logging, idp-backchannel, etc
      • locations of [files] ?
        • could remain in idp-jetty-base/src/main/resources
        • could be GitWeb or downloads/ (possibly deployed via Jenkins)


  • No labels