./security/lasso, Liberty Alliance Single Sign On implementation

[ CVSweb ] [ Homepage ] [ RSS ] [ Required by ] [ Add to tracker ]


Branch: CURRENT, Version: 2.8.2nb2, Package name: lasso-2.8.2nb2, Maintainer: manu

Lasso is a free software C library aiming to implement the Liberty
Alliance standards: ID-FF, ID-WSF and SAML. It defines processes for
federated identities, single sign-on and related protocols. Lasso is
built on top of libxml2, XMLSec and OpenSSL and is GPL licensed.


Required to run:
[textproc/libxml2] [textproc/libxslt] [security/cyrus-sasl] [security/xmlsec1] [security/openssl] [devel/glib2] [lang/py-six]

Required to build:
[lang/python27] [pkgtools/cwrappers]

Master sites:

Filesize: 3929.284 KB

Version history: (Expand)


CVS history: (Expand)


   2026-01-07 09:49:50 by Thomas Klausner | Files touched by this commit (2525)
Log message:
*: recursive bump for icu 78.1
   2025-10-23 22:40:24 by Thomas Klausner | Files touched by this commit (2999)
Log message:
*: recursive bump for pcre2

Running an old binary against the new pcre doesn't work:
/usr/pkg/lib/libpcre2-8.so.0: version PCRE2_10.47 required by \ 
/usr/pkg/lib/libglib-2.0.so.0 not defined
   2025-07-21 10:57:21 by Thomas Klausner | Files touched by this commit (5) | Package updated
Log message:
lasso: update to 2.8.2.

Requested in PR 59536.

2.8.2 - March 14th 2023
-----------------------

- Compatibility with EVP API of openssl 1.x, thanks to Maxime Besson from
  Worteks.

2.8.1 - February 28th 2023
--------------------------

- Major overhaul of OpenSSL API usage by using only the EVP API as the low
  level API (RSA*, HMAC*) is deprecated.
- Fix wrong parsing of Count attribute on saml:ProxyRestriction, thanks to
  Maxime Besson from Worteks.
- Perl: pass LDFLAGS to Makefile.PL
- Replace use of deprecated xmlSecBase64Decode by xmlSecBase64Decode_ex
- Fix overwrite of profile.signature_status in \ 
lasso_saml20_login_process_response_status_and_assertion
- Fix lot of GCC warnings

2.8.0 - March 15th 2022
-----------------------

22 commits, 585 files changed, 2448 insertions, 69478 deletions

* Removal of all win32 and ID-WSF related source code obsoleted a long time ago
* Improve choice of signature method and of allowed signature method (by Jakub
* Hrozek <jhrozek@redhat.com>), it's now possible to completely forbid SHA1 for
  example
* Change default RSA encryption padding to OAEP
* Fix: HMAC signature other than SHA1 (jhrozek@redhat.com)
* Fix: prevent multiple OneTimeUse elements
   2025-04-17 23:53:13 by Thomas Klausner | Files touched by this commit (2449)
Log message:
*: recursive bump for icu 77 and libxml2 2.14
   2024-11-14 23:22:33 by Thomas Klausner | Files touched by this commit (2428)
Log message:
*: recursive bump for icu 76 shlib major version bump
   2024-11-01 13:55:19 by Thomas Klausner | Files touched by this commit (2425)
Log message:
*: revbump for icu downgrade
   2024-11-01 01:54:33 by Thomas Klausner | Files touched by this commit (2426)
Log message:
*: recursive bump for icu 76.1 shlib bump
   2024-05-29 18:35:19 by Adam Ciarcinski | Files touched by this commit (1928) | Package updated
Log message:
revbump after icu and protobuf updates