- Nov 21, 2018
-
-
Guy Halse authored
Change documentation from recommending 2048 bit keys to using 3072 bit keys. Given that we're recommending people generate ten-year keys, 2048 bit keys are probably a bit short. Almost all commercial certificate authorities now recommend 4096 bit keys, and eduGAIN requires 3072 bit keys for new federations. This change aligns the SimpleSAMLphp documentation with the lower eduGAIN requirement, since that still meets most standards bodies recommendations for 2028 (ten years from now). cf https://www.keylength.com/
-
- Nov 16, 2018
-
-
Tim van Dijen authored
-
- Nov 15, 2018
-
-
Guy Halse authored
-
Guy Halse authored
-
Thijs Kinkhorst authored
-
Thijs Kinkhorst authored
-
Tim van Dijen authored
-
- Nov 14, 2018
- Nov 13, 2018
-
-
Thijs Kinkhorst authored
-
Thijs Kinkhorst authored
-
Thijs Kinkhorst authored
-
Thijs Kinkhorst authored
-
Thijs Kinkhorst authored
-
- Oct 20, 2018
-
-
Patrick Radtke authored
-
Patrick Radtke authored
-
- Oct 17, 2018
-
-
Arno van der Vegt authored
-
- Oct 09, 2018
-
-
arno authored
-
- Oct 02, 2018
-
-
Guy Halse authored
-
- Sep 26, 2018
-
-
Tim van Dijen authored
-
Tim van Dijen authored
-
- Sep 25, 2018
-
-
peter authored
Following up on the idea mentioned in #937: If the transport is secure fall back to the `PasswordProtectedTransport` authn context class ref, otherwise keep the current default of `Password`. Requires a version of the SAML2 library with simplesamlphp/saml2#129 merged due to the reference on a newly defined Constant.
-
- Sep 23, 2018
-
-
peter authored
-
- Sep 20, 2018
-
-
Guy Halse authored
-
Guy Halse authored
The SAML2int spec suggests that IdPs should advertise two name identifier formats, and SAML itself supports this. It seems that SimpleSAMLphp does too, when handling metadata in XML (it is implemented as an array). However the internal metadata format uses getString, limiting us to only a single NameIDFormat. So far as I can tell, all that's needed to fix this is to change the metadata parser to use getArrayizeString to accept either a string or an array, and to cast that as a string when necessary. This may solve issue simplesamlphp/simplesamlphp#91
-
- Aug 26, 2018
-
-
Tim van Dijen authored
-
- Aug 22, 2018
-
-
Tim van Dijen authored
-
- Aug 13, 2018
-
-
Tim van Dijen authored
-
- Aug 06, 2018
-
-
Tim van Dijen authored
-
- Aug 05, 2018
-
-
Tim van Dijen authored
-
Tim van Dijen authored
-
- Jul 24, 2018
-
-
Thijs Kinkhorst authored
-
- Jul 18, 2018
-
-
Jaime Pérez Crespo authored
This resolves #888.
-
- Jul 12, 2018
-
-
Tim van Dijen authored
-
- Jul 02, 2018
-
-
Jaime Pérez Crespo authored
The SingleSignOn endpoint is not indexed, and as such, we should prioritize HTTP-Redirect when available in order to comply with SAML2Int.
-
Jaime Pérez Crespo authored
The SingleSignOn endpoint is not indexed, and as such, we should prioritize HTTP-Redirect when available in order to comply with SAML2Int.
-
- Jun 22, 2018
-
-
Thijs Kinkhorst authored
-
- Jun 01, 2018
-
-
Tim van Dijen authored
-
Tim van Dijen authored
-
Tim van Dijen authored
-