They have a thread going on right now. I just posted the link in a separate email to their advisory from like last year :-)
On Fri, Aug 10, 2012 at 10:03 AM, Marvin Addison <marvin.addi...@gmail.com>wrote: > > > http://www.nds.rub.de/media/nds/veroeffentlichungen/2012/08/03/BreakingSAML.pdf > > is an attack report to several SAML based SSO systems to be presented at > USENIX, today. > > I believe the Shib community has been aware of this for some time and > have patched it, though I'm uncertain of the details. I'll do some > research over the next few days and follow up on this thread. > > M > > -- > You are currently subscribed to cas-dev@lists.jasig.org as: > scott.battag...@gmail.com > To unsubscribe, change settings or access archives, see > http://www.ja-sig.org/wiki/display/JSG/cas-dev > -- You are currently subscribed to cas-dev@lists.jasig.org as: arch...@mail-archive.com To unsubscribe, change settings or access archives, see http://www.ja-sig.org/wiki/display/JSG/cas-dev