Package: opensaml / 3.3.1-4
Metadata
| Package | Version | Patches format |
|---|---|---|
| opensaml | 3.3.1-4 | 3.0 (quilt) |
Patch series
view the series file| Patch | File delta | Description |
|---|---|---|
| Update SAML2 signatures to RSA SHA256.patch | (download) |
samltest/data/saml2/core/impl/ResponseChildElements.xml |
2 1 + 1 - 0 ! |
update saml2 signatures to rsa-sha256 The default signature algorithm changed to RSA-SHA256 in XMLTooling 3.3 [1], so the control XML files in the OpenSAML test suite must follow [2]. The "Not yet signed" ResponseChildElements.xml was edited manually, while SAML2Assertion.xml was re-signed in the build tree via ../samlsign/samlsign -s -k ./data/key.pem -c ./data/cert.pem -f ./data/signature/SAML2Assertion.xml [1] https://shibboleth.atlassian.net/browse/CPPXT-162 [2] https://shibboleth.atlassian.net/browse/CPPOST-125 |
| Skip SAML1 tests depending on the old RSA SHA1 default si.patch | (download) |
samltest/signature/SAML1AssertionTest.h |
1 1 + 0 - 0 ! |
skip saml1 tests depending on the old rsa-sha1 default signature I do not know how to re-sign SAML1 data with RSA-SHA256. |
| Use the new InCommon metadata source.patch | (download) |
samltest/data/incommon.pem |
60 26 + 34 - 0 ! |
use the new incommon metadata source The legacy metadata expired on 2025-04-15, leading to failures in the XMLMetadataProviderTest samltest suite. The new URL and certificate was taken from the https://spaces.at.internet2.edu/display/MDQ/how-to-locate-metadata-with-mdq page. |
| Disable SHORT_NAMES in Doxygen to gain reproducibility.patch | (download) |
doxygen.cfg |
2 1 + 1 - 0 ! |
disable short_names in doxygen to gain reproducibility |
| Extend test metadata assertion validity to 2031.patch | (download) |
samltest/data/binding/example-metadata.xml |
2 1 + 1 - 0 ! |
extend test metadata/assertion validity to 2031 It would be better to use dynamic expiration dates, but this small change fixes the problem for forky. Closes: #1127130 |
