A conference call sounds great. Besides from content and issues to address 
I???d 
also like to discuss timeline and release strategy. It would be great if we 
could come up with a release date, and what we could fit in given bandwidth 
and resources I have been review pending pulls and merging those that were 
previously intended for 4.0 or 4.1 but I will also try to mark a number of 
candidate JIRAs for 4.1 and have the team review and comment on feasibility.



I am available on the week of May 26th, as of now, pretty much any day/time.



From: J??r??me LELEU [mailto:[email protected]]
Sent: Monday, May 19, 2014 3:31 AM
To: [email protected]
Subject: [cas-dev] CAS 4.1.0



Hi,



CAS 4.0 has been released and I'm almost done with the tasks on the Jasig 
web site.



So it's time to think about the future (I like to say that ;-). Maybe we 
could organize some conf call to talk about the next features we want to 
work on?



At our last AppSec Working Group conf call, we tried to prioritize what we 
could expect from a security point of view.

From: 
https://wiki.jasig.org/display/CAS/Proposals+to+mitigate+security+risks, we 
highlighted:

-- global secure flag to enable HTTP on service / proxy (SEC_2b / SEC_1)

- SEC_4 + SEC_5

- SEC_7 + SEC_9

- SEC_10.



This is of course some starting point for a discussion.



I'm looking forward to your feedbacks.



Thanks.

Best regards,

J??r??me




-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-dev

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-dev

Reply via email to