Shibboleth Identity Provider Security Advisory with new minor version release
Posted on Thursday, 28 August 2025
The UK federation recommends adhering to best practices by routinely managing patches for your IdP environment. This includes subscribing to future security notifications:Shibboleth Announce.
Following the recent security advisory from the Shibboleth Consortium regarding the IdP, you should update your Identity Provider software to version 5.1.6 (or later) at your earliest convenience. Although the affected code path is likely not in use by the UK federation userbase, updating will help mitigate any potential exploits.
As ever, please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk
Audience
While this advisory is directed only at operators of the Shibboleth IdP rather than other entities within the UK federation, it is good practice to be subscribed to the appropriate mailing lists for any software you operate in order to stay abreast of the need for updates.
read more... Edited by SteveGlover
FAM 25 Presentations
Posted on Tuesday, 8 July 2025
We hope you enjoy the slide presentations and some recordings from the FAM 25 event held in Manchester on July 2nd 2025.
They include:
read more... Edited by SteveGlover
Shibboleth Identity Provider Security Advisory
Posted on Monday, 31 March 2025
The UK federation recommends adhering to best practices by routinely managing patches for your IdP environment. This includes subscribing to future security notifications:Shibboleth Announce.
Following the recent low-level security advisory from the Shibboleth Consortium regarding the IdP, you should update your Identity Provider software to version 5.1.4 (or later) at your earliest convenience. Although the affected code path is likely not in use by the UK federation userbase, updating will help mitigate any potential exploits.
Please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk
read more... Edited by MattHuckson
Security Advisory: Critical flaw in OpenSAML affecting Shibboleth Service Provider
Posted on Friday, 14 March 2025
The Shibboleth Project last night released an update and security advisory to the OpenSAML library used by the Shibboleth Service Provider. The Shibboleth developers have assessed this issue and determined its impact to be critical.
Recommended Actions:
- Update to version 3.3.1 (or later) of the OpenSAML library package as soon as possible and also subscribe to future notifications .
Detailed instructions are provided in the advisory.
Please ensure your software versions are patched promptly. If you have any questions or queries then please do contact the UK federation service desk.
read more... Edited by MattHuckson