You can follow this space for news about the project and software releases, though it is strongly advised that you subscribe to the announce mailing list instead. There may be lag in important information appearing here.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20180112.txt that involves the XML processing performed by the Service Provider on a subset of platforms limited to an older version of the Xerces library. An xmltooling patch update, V1.6.3, is available that corrects the issue on platforms not already protected by an updated XML parser.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20171115.txt that involves the Dynamic MetadataProvider feature in the Service Provider. A patch update, V2.6.1, is available http://shibboleth.net/pipermail/announce/2017-November/000168.html that corrects the issue.
The Shibboleth Project has released V2.6.1 of the Service Provider software, to correct a security issue https://shibboleth.net/community/advisories/secadv_20171115.txt.
Release notes for this release and previous versions are here https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPReleaseNotes.
The Shibboleth Project has announced http://shibboleth.net/pipermail/announce/2017-October/000166.html the release of V3.3.2 https://shibboleth.net/downloads/identity-provider/3.3.2/ of the Identity Provider software, a patch upgrade. This release is in conjunction with a security advisory https://shibboleth.net/community/advisories/secadv_20171004.txt.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20171004.txt that involves a potential MITM attack against LDAP data connections using "ldaps". A patch release is now available https://shibboleth.net/downloads/identity-provider/3.3.2/ that corrects the issue and takes steps to prevent its recurrence.
The Consortium announced http://shibboleth.net/pipermail/announce/2017-August/000163.html a change coming in the near future to the subsidization of technical support via our development team. The change, in brief, is that the Consortium will be funding the development team to provide technical support only to actual members https://www.shibboleth.net/consortium/ of the Consortium and not to the community at large. An open support list for the community will continue to exist,…
The Shibboleth Consortium board held a pair of webinars on March 29th to outline the state of the consortium's finances and begin to gather input from members and non-members on next steps to address sustainability. The slides from this introductory session are available from http://shibboleth.net/documents/ShibCommunityWebinar-2017-03-29.pdf http://shibboleth.net/documents/ShibCommunityWebinar-2017-03-29.pdf
The Shibboleth Project has announced http://shibboleth.net/pipermail/announce/2017-March/000157.html the release of V3.3.1 http://shibboleth.net/downloads/identity-provider/3.3.1/ of the Identity Provider software, a patch upgrade. This release is in conjunction with a security advisory https://shibboleth.net/community/advisories/secadv_20170315.txt.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20170315.txt that involves possibly bypass of second factor authentication requirements in certain less common scenarios described in the advisory. A patch release is now available https://shibboleth.net/downloads/identity-provider/3.3.1/ that corrects the issue.
The Shibboleth Project has announced http://shibboleth.net/pipermail/announce/2016-November/000154.html the release of V3.3.0 https://shibboleth.net/downloads/identity-provider/3.3.0/ of the Identity Provider software, a major feature upgrade.
This release is in conjunction with an OpenSAML-J feature release, V3.3.0.
A service update to the Windows Service Provider installers is now available to deliver updated versions of OpenSSL and libcurl to address minor security issues in those libraries. Details are in the announcement http://shibboleth.net/pipermail/announce/2016-November/000153.html.
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20161027.txt that involves the LDAPConnector feature in the Identity Provider. The advisory describes a temporary workaround, and a forthcoming IdP release due within the next few weeks will permanently correct the issue.
The Shibboleth Project has released V2.6.0 of the Service Provider software, the first feature upgrade in several years.
This release includes a permanent fix for the security issue described in the advisory https://shibboleth.net/community/advisories/secadv_20160504.txt last month, a number of other new features and bug fixes, and (on Windows) includes a new version of the Xerces XML parser that addresses a vulnerability http://xerces.apache.org/xerces-c/secadv/CVE-2016-4463.…
The Shibboleth Project has released a security advisory https://shibboleth.net/community/advisories/secadv_20160504.txt that involves the PathRegex feature in the Service Provider. The advisory describes a temporary workaround, and a forthcoming SP release this summer will provide a permanent solution.
The Shibboleth Project has released V2.5.6 http://shibboleth.net/downloads/service-provider/2.5.6/ of the Service Provider software, a bug fix release that also addresses a security issue https://shibboleth.net/pipermail/announce/2016-February/000141.html in the Xerces XML parser used by the software.
Recently, a group of physicists at The Laser Interferometer Gravitational Wave Observatory (LIGO) completed work detecting gravitational waves http://www.nytimes.com/2016/02/12/science/ligo-gravitational-waves-black-holes-einstein.html?_r=0. This confirms a major prediction of Albert Einstein's 1915 general theory of relativity and opens an unprecedented new window into the cosmos.
The Shibboleth Consortium is proud to have LIGO as a member http://shibboleth.net/consortium/,…
The Shibboleth Project has announced the release of V2.4.5 http://shibboleth.net/downloads/identity-provider/2.4.5/ of the Identity Provider software, a patch release to address bugs reported since the V2.4.4 release
This release is in conjunction with an OpenSAML-J patch release, V2.6.6 http://shibboleth.net/downloads/java-opensaml/2.6.6/
These releases are the last non-security releases for both V2 projects prior to the full End-Of-Life of both projects on July 31, 2016.…