PAPI Archivos

The PAPI authentication and authorization framework

PAPI@LISTSERV.REDIRIS.ES

Opciones: Vista Forum

Use Proportional Font
Por defecto enseñar Text Part
Esconda cabeceras de correo

Mensaje: [<< Primero] [< Prev] [Siguiente >] [Último >>]
Tema: [<< Primero] [< Prev] [Siguiente >] [Último >>]
Autor: [<< Primero] [< Prev] [Siguiente >] [Último >>]

Print Responder
Received:
from LISTSERV.REDIRIS.ES by LISTSERV.REDIRIS.ES (LISTSERV-TCP/IP release 1.8e) with spool id 24715930 for [log in para visualizar]; Mon, 24 May 2004 18:00:23 +0200 from relay.rediris.es (relay.rediris.es [130.206.1.53]) by chico.rediris.es (8.12.10/8.9.1) with ESMTP id i4OG0MQK007904 for <[log in para visualizar]>; Mon, 24 May 2004 18:00:22 +0200 (CEST) from chico.rediris.es (chico.rediris.es [130.206.1.3])by relay.red iris.es (8.12.11/8.11.1) with ESMTP id i4OG0M3Q006335for <[log in para visualizar] iris.es>; Mon, 24 May 2004 18:00:22 +0200 from metanave.rediris.es (metanave.rediris.es [130.206.194.37])by chico.rediris.es (8.12.10/8.9.1) with ESMTP id i4OG0Lmp007899for <papi@list serv.rediris.es>; Mon, 24 May 2004 18:00:22 +0200 (CEST)
Content-Type:
text/plain
X-imss-settings:
Baseline:4 C:4 M:4 S:4 R:4 (0.1000 0.1000)
Date:
Mon, 24 May 2004 18:00:21 +0200
Subject:
X-imss-result:
Passed
Reply-To:
The PAPI authentication and authorization framework <[log in para visualizar]>
Emisor:
"Diego R. Lopez" <[log in para visualizar]>
Sender:
The PAPI authentication and authorization framework <[log in para visualizar]>
Message-ID:
<1085414421.1366.41.camel@incal>
Content-Transfer-Encoding:
7bit
Mime-Version:
1.0
X-imss-scores:
Clean:50.05719 C:2 M:7 S:5 R:5
X-Mailer:
Ximian Evolution 1.4.3
X-imss-version:
2.0
Parts/Attachments:
text/plain (64 lines)
Dear friends,

The PAPI Development Team is proud to announce the new PAPI 1.3.1. This
new version is available at the PAPI web site http://papi.rediris.es/

This release mostly includes several bug fixes (notably, the one
dealing with the security problem discovered last March), although it
also introduces new features that have been requested by user
organizations. We enclose here a list of the main changes from the
previous version (1.3.0) from the PAPI release notes:

- Correct two security flaws in the code of the AuthServer that could
  allow an attacker to impersonate a valid user under some
  circumstances. Thanks to Diego Ray ([log in para visualizar]) from the
  University of Malaga for detecting the bugs and preparing a exploit
  demonstration program.

- A new algorithm for access token rotation has been implemented. The
  Max_Nonce_Errors directive has been introduced to configure this
  algorithm.

- The built-in WAYF is able to automatically redirect a request (without
  user interaction) when just one AS is recognized by the PoA.
  Contributed by Luis Melendez ([log in para visualizar]) from the University of
  Cordoba.

- It is possible to call external procedures at the PoA to generate the
  contents of access tokens from the data received in the assertion (by
  means of the Hcook_Generator directive).

- Enhance the proxy behavior to deal with comment-protected JavaScript
  snippets and (non-standard but widely used) Refresh headers.

- Add the new configuration directive Reject_URL_Pattern, to allow a
  finer control over proxied URLs.

- The LDAPAuth module is now able to access LDAP servers (for validating
  users and retrieving attributes) via a TLS connection. Thanks to Oriol
  Rico ([log in para visualizar]) from UPC for his help in testing this.

- A new configuration variable, uidVar, has been included into the
  AuthServer, so a user identifier can be used even for those operations
  (like TEST and LOGOUT) for which fully user identification is not
  mandatory.

- Correct a bug in the IMAPAuth module that precluded users with empty
  mailboxes from successfully logging-in. Contributed by Luis Melendez
  ([log in para visualizar]) from the University of Cordoba.

Enjoy,
--
"Esta vez no fallaremos, Doctor Infierno"

Dr Diego R. Lopez

Red.es - RedIRIS
The Spanish NREN

e-mail: [log in para visualizar]
jid:    [log in para visualizar]
Tel:    +34 955 056 621
Mobile: +34 669 898 094
-----------------------------------------

ATOM RSS1 RSS2