UK federation News
Shibboleth Identity Provider Security Advisory with new minor version release
Posted on Thursday, 28 August 2025
The UK federation recommends adhering to best practices by routinely managing patches for your IdP environment. This includes subscribing to future security notifications:Shibboleth Announce.
Following the recent security advisory from the Shibboleth Consortium regarding the IdP, you should update your Identity Provider software to version 5.1.6 (or later) at your earliest convenience. Although the affected code path is likely not in use by the UK federation userbase, updating will help mitigate any potential exploits.
As ever, please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk
Audience
While this advisory is directed only at operators of the Shibboleth IdP rather than other entities within the UK federation, it is good practice to be subscribed to the appropriate mailing lists for any software you operate in order to stay abreast of the need for updates.
read more... Edited by SteveGlover
FAM 25 Presentations
Posted on Tuesday, 8 July 2025
We hope you enjoy the slide presentations and some recordings from the FAM 25 event held in Manchester on July 2nd 2025.
They include:
read more... Edited by SteveGlover
Shibboleth Identity Provider Security Advisory
Posted on Monday, 31 March 2025
The UK federation recommends adhering to best practices by routinely managing patches for your IdP environment. This includes subscribing to future security notifications:Shibboleth Announce.
Following the recent low-level security advisory from the Shibboleth Consortium regarding the IdP, you should update your Identity Provider software to version 5.1.4 (or later) at your earliest convenience. Although the affected code path is likely not in use by the UK federation userbase, updating will help mitigate any potential exploits.
Please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk
read more... Edited by MattHuckson
Security Advisory: Critical flaw in OpenSAML affecting Shibboleth Service Provider
Posted on Friday, 14 March 2025
The Shibboleth Project last night released an update and security advisory to the OpenSAML library used by the Shibboleth Service Provider. The Shibboleth developers have assessed this issue and determined its impact to be critical.
Recommended Actions:
- Update to version 3.3.1 (or later) of the OpenSAML library package as soon as possible and also subscribe to future notifications .
Detailed instructions are provided in the advisory.
Please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk.
read more... Edited by MattHuckson
UK federation service desk closure for Winter break 2024-2025
Posted on Thursday, 12 December 2024
As with most areas of Jisc, the UK federation service desk will be taking an extended break over Christmas and New Year. The helpdesk will be unavailable from 12:00 on Tuesday, 24th December 2024, and will reopen at 10:00 on Thursday, 2nd January 2025. If you submit a request to service@ukfederation.org.uk during this period, your email will be logged, but we won't be able to respond until we return. Please note that any metadata changes need to be submitted by 19th December to be considered for publication; otherwise, they will be addressed from 2nd January 2025 onwards.
UK federation metadata will be automatically re-published over the holiday period. While we won't make changes to UK federation-registered entities, there may be updates due to entities imported via eduGAIN.
read more... Edited by MattHuckson