shibboleth-sp/shibboleth-sp.changes

232 lines
9.0 KiB
Plaintext

-------------------------------------------------------------------
Wed Nov 6 21:16:56 UTC 2024 - Antonio Teixeira <antonio.teixeira@suse.com>
- Update to 3.5.0:
* This is a small update to address a few bugs, update a number of libraries,
and implement a correction to the default signing algorithm used when
issuing signed requests via the SAML POST binding. This was inadvertently
still defaulting to RSA-SHA1 and should have been using RSA-SHA256.
There is the unlikely possibility of this causing interoperability issues
with badly out of date Identity Providers, so is another reason for
releasing it as a minor update.
-------------------------------------------------------------------
Fri Feb 9 10:58:52 UTC 2024 - Daniel Molkentin <daniel@molkentin.de>
- create correct user name runuser, not realname
-------------------------------------------------------------------
Mon Feb 5 12:01:14 UTC 2024 - Daniel Molkentin <daniel@molkentin.de>
- Update to use sysuser pattern
- Fix build warnings
-------------------------------------------------------------------
Tue Jan 17 08:57:09 UTC 2023 - Dirk Müller <dmueller@suse.com>
- update to 3.4.1:
* Reinforcing the xmltooling library (V3.2.3, included in this Windows release)
to block an unnecessary XML Encryption construct, related to the advisory
issued for the IdP recently. The SP is not believed to be vulnerable, but this
is a defensive measure.
* A warning has been added to the log when systems do not configure an explicit
value for the redirectLimit setting. The default for this setting remains
liberal for compatibility, so the warning was requested to highlight that
fact.
-------------------------------------------------------------------
Thu Nov 17 16:56:40 UTC 2022 - Danilo Spinella <danilo.spinella@suse.com>
- Updaet to 3.4.0:
* Add a new setting suggested controlling retries when TCP connections
to shibd are used.
- Change libraries soname from 10 to 11
-------------------------------------------------------------------
Wed Dec 1 09:32:43 UTC 2021 - Danilo Spinella <danilo.spinella@suse.com>
- Update to 3.3.0:
* This is a minor update that contains a small number of fixes,
one small feature addition, and a number of additional deprecation
warnings for at risk features.
-------------------------------------------------------------------
Wed Nov 17 08:21:48 UTC 2021 - Johannes Segitz <jsegitz@suse.com>
- Added hardening to systemd service(s) (bsc#1181400). Modified:
* shibd.service
-------------------------------------------------------------------
Tue Jul 13 16:07:01 UTC 2021 - Danilo Spinella <danilo.spinella@suse.com>
- Update to 3.2.3:
* This is a minor update that includes some minimal new functionality and addresses some bugs.
* Fix two different security bugs (secadv_20210317 and secadv_20210426)
- Run spec-cleaner
- Change library soname from 9 to 10
- Change lite library soname from 8 to 10
-------------------------------------------------------------------
Tue Dec 1 13:27:30 UTC 2020 - Kristyna Streitova <kstreitova@suse.com>
- Update to 3.1.0
* list of fixes and enhancements
https://wiki.shibboleth.net/confluence/display/SP3/ReleaseNotes
- Update xmltooling and opensaml versions in "Requires"
- Change library soname from 8 to 9
-------------------------------------------------------------------
Wed Aug 19 11:27:22 UTC 2020 - Dominique Leuenberger <dimstar@opensuse.org>
- Rely on the distro-provided macros for tmpfilesdir. All half-way
current distros define this already.
-------------------------------------------------------------------
Wed Jan 8 11:40:04 UTC 2020 - Dominique Leuenberger <dimstar@opensuse.org>
- BuildRequire pkgconfig(libsystemd) instead of systemd-devel:
Allow OBS to shortcut through the -mini flavors.
-------------------------------------------------------------------
Mon Dec 2 10:36:30 UTC 2019 - Kristyna Streitova <kstreitova@suse.com>
- remove fixing of the ownership of log files as this allows shibd
to escalate to root [bsc#1157471] [CVE-2019-19191]
- generate two keys on new installs instead of just one
-------------------------------------------------------------------
Fri Apr 26 10:46:00 UTC 2019 - mvetter@suse.com
- bsc#1130588: Require shadow instead of old pwdutils
-------------------------------------------------------------------
Wed Mar 20 13:06:50 UTC 2019 - Kristýna Streitová <kstreitova@suse.com>
- update to 3.0.4
* list of fixes and enhancements
https://issues.shibboleth.net/jira/browse/SSPCPP-851?filter=12771
- update xmltooling and opensaml versions in "Requires"
-------------------------------------------------------------------
Mon Feb 11 19:02:26 UTC 2019 - Jan Engelhardt <jengelh@inai.de>
- Trim redundancies from summary
-------------------------------------------------------------------
Mon Feb 11 13:42:19 UTC 2019 - kstreitova@suse.com
- update to 3.0.3
* list of fixes and enhancements
https://issues.shibboleth.net/jira/browse/SSPCPP-845?filter=12573
-------------------------------------------------------------------
Wed Nov 28 13:24:28 UTC 2018 - kstreitova@suse.com
- update to 3.0.2
* list of fixes and enhancements
https://wiki.shibboleth.net/confluence/display/SP3/ReleaseNotes
- remove shibboleth-sp-2.5.6-libsystemd-daemon.patch that is no
longer needed
- update package filelist
- change library soname from 7 to 8
- update dependencies versions
-------------------------------------------------------------------
Wed Nov 15 12:50:45 UTC 2017 - kstreitova@suse.com
- update to 2.6.1
* list of fixes and enhancements
https://issues.shibboleth.net/jira/browse/SSPCPP-760?filter=12270
* fixes [bsc#1068689] [CVE-2017-16852]
-------------------------------------------------------------------
Thu Sep 21 16:34:48 UTC 2017 - kstreitova@suse.com
- update to 2.6.0
* list of fixes and enhancements
https://issues.shibboleth.net/jira/browse/SSPCPP-716?filter=11475
- update soname for libshibsp from 6 to 7
- adjust BuildRequires of boost
* libboost_headers-devel for openSUSE:Factory
* boost-devel for older distros
- update versions of BuildRequires for opensaml (>= 2.6.0) and
libxmltooling (>= 1.6.0)
- shibd.service: increase TimeoutStartSec to 150s (as upstream did)
- remove %{_sysconfdir}/%{realname}/*.xsl from filelist (it is no
longer present)
- run spec-cleaner
-------------------------------------------------------------------
Thu Mar 16 11:12:11 UTC 2017 - kstreitova@suse.com
- fix build for openSUSE:Leap:42.1 by adding %define for
tmpfiles_create as this macro doesn't exist there
-------------------------------------------------------------------
Tue Feb 14 14:57:07 UTC 2017 - kstreitova@suse.com
- add shibboleth-sp-2.5.6-libsystemd-daemon.patch to fix configure
to use libsystemd instead of obsolete libsystemd-daemon.
Regenerate configure via autoreconf and add autoconf and automake
BuildRequires.
-------------------------------------------------------------------
Tue Jul 19 18:11:33 UTC 2016 - dimstar@opensuse.org
- Use %tmpfiles_create macro: gracefully fails in case of missing
binaries (e.g. container setups).
-------------------------------------------------------------------
Wed May 11 13:34:20 UTC 2016 - kstreitova@suse.com
- build libmemcached support
-------------------------------------------------------------------
Fri Apr 8 12:08:41 UTC 2016 - kstreitova@suse.com
- update to shibboleth-sp 2.5.6
* Update solution file after loading into VS2015
* SSPCPP-669 - cached samlds.json files prematurely removed w/ multiple
* applicationIds
* SSPCPP-671 - Handling of partial success in LogoutResponse needs work
* Fix line feeds again, VS is also broken
* SSPCPP-670 - Session Cleanup for Database Session Storage can cause performance issues
* Re-convert linefeeds to undo Eclipse's handiwork
* SSPCPP-675 - configuration sample cites "federation.org"
* Clean up ignores
* Apply typo fixes provided by Debian packagers
* Update library/software version
* Update MSI names to carry patch version
* SSPCPP-665 - Use of systemd breaks on reboot
-------------------------------------------------------------------
Wed Aug 5 18:09:37 UTC 2015 - mpluskal@suse.com
- Add gpg signature
-------------------------------------------------------------------
Thu Jul 30 13:51:20 UTC 2015 - kstreitova@suse.com
- fix some warnings
- add service as a separate file
- remove command line switches for conditional package builds
- remove *.dist files and unused *.config files
- remove unused conditionals
- move libraries to the subpackages
-------------------------------------------------------------------
Mon Jul 27 16:30:58 UTC 2015 - kstreitova@suse.com
- use spec-cleaner
- package cleaning
- add shibboleth-sp-2.5.5-doxygen_timestamp.patch to remove
timestamps in a documentation generated by Doxygen and avoid
RPMLINT warnings (file-contains-date-and-time).
- add the macro %{realname} and change a name to "shibboleth-sp"
- fix Source address
-------------------------------------------------------------------
Fri Jul 24 14:44:04 UTC 2015 - kstreitova@suse.com
- initial revision