Re: Public discussion on future of C++ library

2024-03-07 Thread Colm O hEigeartaigh
+1 from me. Colm. On Thu, Mar 7, 2024 at 2:20 PM Cantor, Scott wrote: > > > IMO yes we should have a vote to retire the project at ASF, obviously > > it's just a formality at this stage. > > Ok. Obviously this is my +1. > > -- Scott > >

Re: Public discussion on future of C++ library

2024-03-06 Thread Colm O hEigeartaigh
IMO yes we should have a vote to retire the project at ASF, obviously it's just a formality at this stage. Colm. On Wed, Mar 6, 2024 at 4:18 PM Cantor, Scott wrote: > > > I can begin the import/migration process if you don't feel the need for a > > formal vote to approve this step. > > Even

Re: Public discussion on future of C++ library

2024-03-05 Thread Colm O hEigeartaigh
Hi Scott, I think on the ASF side we would just add a note to the README in the repo saying the project is no longer maintained and a updated version is available at Shibboleth, and to update the website as well. I don't think we need to do anything regarding "migrating" as such, from our PoV the

Re: Public discussion on future of C++ library

2024-02-23 Thread Colm O hEigeartaigh
Hey Scott, As you are the sole maintainer, IMO it's your decision to make. Personally I'd be fine with Option (2), but are you willing to maintain the code, review any rare patches submitted, release sporadically etc.? Otherwise I think it's time to archive the project. Colm. Cop;l, On Wed,

Re: [VOTE] - Release Apache Santuario - XML Security for Java 4.0.2/3.0.4

2024-02-22 Thread Colm O hEigeartaigh
With 6 +1 votes, including at least 3 binding votes, and no other votes, this vote passes. Colm. On Tue, Feb 20, 2024 at 2:27 PM Sean Mullan wrote: > > +1 > > --Sean > > On 2/19/24 5:38 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario

[VOTE] - Release Apache Santuario - XML Security for Java 4.0.2/3.0.4

2024-02-19 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 4.0.2 and 3.0.4. They contain a new feature to support Key Agreement using ECDH-ES. 4.0.2: Release notes: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12353948 Git tag:

Re: [VOTE] - Release Apache Santuario - XML Security for Java 4.0.1

2023-11-27 Thread Colm O hEigeartaigh
With 4 +1 votes, and at least 3 binding votes, this vote passes. Colm. On Mon, Nov 27, 2023 at 4:14 PM Sean Mullan wrote: > > +1. > > —Sean > > > On Nov 24, 2023, at 9:50 AM, Colm O hEigeartaigh > > wrote: > > > > This is a vote to release Apache Sa

[VOTE] - Release Apache Santuario - XML Security for Java 4.0.1

2023-11-24 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario XML Security for Java 4.0.1. It contains a bug fix https://issues.apache.org/jira/browse/SANTUARIO-609 "Remove call to Signature.getProvider() in debug log" Artifacts: https://repository.apache.org/content/repositories/orgapachesantuario-1046/ Git tag:

CVE-2023-44483: Apache Santuario: Private Key disclosure in debug-log output

2023-10-20 Thread Colm O hEigeartaigh
Severity: moderate Affected versions: - Apache Santuario before < 2.2.6 - Apache Santuario before < 2.3.4 - Apache Santuario before < 3.0.3 Description: All versions of Apache Santuario - XML Security for Java prior to 2.2.6, 2.3.4, and 3.0.3, when using the JSR 105 API, are vulnerable to

Re: [VOTE] - Release Apache Santuario - XML Security for Java 3.0.3, 2.3.4 and 2.2.6

2023-10-18 Thread Colm O hEigeartaigh
With 4 binding +1 votes and no other votes, the vote passes. I'll do the release. Colm. On Mon, Oct 16, 2023 at 1:48 PM Daniel Kulp wrote: > > +1 > Dan > > > On Oct 16, 2023, at 8:18 AM, Sean Mullan wrote: > > +1 > > —Sean > > On Oct 13, 2023, at

Re: [VOTE] - Release Apache Santuario - XML Security for Java 4.0.0

2023-10-18 Thread Colm O hEigeartaigh
With 4 binding +1 votes and no other votes, the vote passes. I'll do the release. Colm. On Mon, Oct 16, 2023 at 1:47 PM Daniel Kulp wrote: > > +1 > > Dan > > > On Oct 13, 2023, at 9:39 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario - XM

[VOTE] - Release Apache Santuario - XML Security for Java 3.0.3, 2.3.4 and 2.2.6

2023-10-13 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 3.0.3, 2.3.4 and 2.2.6. These are all bug fix releases. All artifacts are in the same maven repo for release: https://repository.apache.org/content/repositories/orgapachesantuario-1045/ 3.0.3 git tag:

[VOTE] - Release Apache Santuario - XML Security for Java 4.0.0

2023-10-13 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 4.0.0. 4.0.0 is a new major release with the following features: - Java 11 requirement - Removing SLF4J and using System.Logger - AutoCloseable for several types Artifacts:

Re: New releases

2023-10-11 Thread Colm O hEigeartaigh
if I provide the initial PR next week, is there any chance > to have released this feature at the beginning of 2024 for all the libraries > up to cxf-rt-ws-security? > > Best regards > Joze > > On Tue, 10 Oct 2023 at 11:14, Colm O hEigeartaigh wrote: >> >> Hi, >>

New releases

2023-10-10 Thread Colm O hEigeartaigh
Hi, I intend to call votes on new releases of the 3.0.x, 2.3.x and 2.2.x branches before the end of the week. Please shout now if anything else should go into these releases. Colm.

New releases

2023-09-19 Thread Colm O hEigeartaigh
I'd like to get 3.0.3 + 2.3.4 out soon, is there anything remaining that should go into the releases? Colm.

Re: [VOTE] - Release Apache Santuario - XML Security for Java 4.0.0-M1

2023-09-05 Thread Colm O hEigeartaigh
With 4 +1 votes and no other votes, this vote passes. I'll do the release. Colm. On Tue, Sep 5, 2023 at 5:01 PM Alessio Soldano wrote: > > +1 > Thanks! > > On Mon, Aug 28, 2023 at 3:22 PM Colm O hEigeartaigh > wrote: >> >> This is a vote to release Apache San

[VOTE] - Release Apache Santuario - XML Security for Java 4.0.0-M1

2023-08-28 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 4.0.0-M1. It is a milestone release and not meant for production. The main new features of the release come from this PR https://github.com/apache/santuario-xml-security-java/pull/192 - Java 11 requirement - Removing SLF4J and

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.5

2023-08-18 Thread Colm O hEigeartaigh
With 6 +1 votes, and at least 3 binding +1 votes, and no other votes this vote passes. I'll do the release. Colm. On Wed, Aug 16, 2023 at 9:27 PM Alessio Soldano wrote: > > +1, thanks > > On Tue, Aug 15, 2023 at 1:36 PM Colm O hEigeartaigh > wrote: >> >> This

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.5

2023-08-16 Thread Colm O hEigeartaigh
Hi Scott, You can review all changes between 2.2.5 and 2.2.4 here: https://github.com/apache/santuario-xml-security-java/compare/xmlsec-2.2.4...xmlsec-2.2.5 Essentially it's just Xalan, BouncyCastle, Woodstox and Jetty upgrades. Colm. On Tue, Aug 15, 2023 at 3:34 PM Cantor, Scott wrote: > > >

[VOTE] - Release Apache Santuario - XML Security for Java 2.2.5

2023-08-15 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.2.5. It just contains some dependency updates to fix CVEs. Artifacts: https://repository.apache.org/content/repositories/orgapachesantuario-1041/ Git tag:

[VOTE] - Release Apache Santuario - XML Security for Java 3.0.2 and 2.3.3

2023-03-27 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 3.0.2 and 2.3.3. 3.0.2: - Issues fixed: https://issues.apache.org/jira/projects/SANTUARIO/versions/12352305 - Artifacts: https://repository.apache.org/content/repositories/orgapachesantuario-1039/ - Git tag:

New Java releases

2023-03-21 Thread Colm O hEigeartaigh
Hi, I propose to call votes next week on new Java releases to get the EdDSA contribution released, let me know please if there is anything else that should make it in. Colm.

Re: Failing builds

2023-02-01 Thread Colm O hEigeartaigh
The JDK8 version has been updated in Jenkins and the build is passing again. Colm. On Fri, Jan 20, 2023 at 11:15 AM Colm O hEigeartaigh wrote: > > Hi, > > FYI the JDK8 builds are failing with the recent EdDSA commit, as the > JDK version is too old (1.8.0_291). I've filed a re

Failing builds

2023-01-20 Thread Colm O hEigeartaigh
Hi, FYI the JDK8 builds are failing with the recent EdDSA commit, as the JDK version is too old (1.8.0_291). I've filed a request for INFRA to upgrade: https://issues.apache.org/jira/browse/INFRA-24102 Colm.

Re: [VOTE] - Release Apache Santuario - XML Security for Java 3.0.1 and 2.3.2

2022-09-16 Thread Colm O hEigeartaigh
With 5 +1 votes, and no other votes, this vote passes. Colm. On Thu, Sep 15, 2022 at 8:05 AM Alessio Soldano wrote: > > +1 > thanks! > > On Mon, Sep 12, 2022 at 5:13 PM Colm O hEigeartaigh > wrote: >> >> This is a vote to release Apache Santuario - XML Securi

[VOTE] - Release Apache Santuario - XML Security for Java 3.0.1 and 2.3.2

2022-09-12 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 3.0.1 and 2.3.2. The main change is to remove Xalan as a provided (optional) dependency. 3.0.1: Issues fixed: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12351689 Git tag:

New releases

2022-09-05 Thread Colm O hEigeartaigh
Hi all, Let's get new Java releases out soon - 2.3.2 and 3.0.1. Let me know if there is anything left to go into these releases. Colm.

Default branch change in github/gitbox for the santuario-xml-security-java

2022-09-01 Thread Colm O hEigeartaigh
Hi all, As discussed some time ago on the mailing list, the default branch of santuario-xml-security-java has changed from master to main. Please update your local checkouts accordingly. Colm.

Re: Remove Xalan and here() function support

2022-09-01 Thread Colm O hEigeartaigh
at > > it should have been defined in a namespace in order to be properly > > processed as an XPath extension. > > > > --Sean > > > > On 8/30/22 4:04 AM, Colm O hEigeartaigh wrote: > >> Hi all, > >> > >> I'd like to propose removing Xalan as an (optio

Remove Xalan and here() function support

2022-08-30 Thread Colm O hEigeartaigh
Hi all, I'd like to propose removing Xalan as an (optional) dependency and also support as a result for the here() function defined in the spec: https://www.w3.org/TR/xmldsig-core1/#function-here To re-cap, currently for XPath we use the default Java implementation. Xalan is an optional

Switching Git default branch to main

2022-07-06 Thread Colm O hEigeartaigh
Hi all, Unless I hear some strong objections I intend to file a JIRA with INFRA to switch the default branch of the java git project from "master" to "main". For some time any new GitHub project uses "main" as the default branch, and most of the Apache projects I work with (ActiveMQ, CXF, Karaf,

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.1.8

2022-05-03 Thread Colm O hEigeartaigh
With 5 +1 votes, this vote passes. I'll do the release. Colm. On Mon, May 2, 2022 at 5:08 PM Daniel Kulp wrote: > > +1 > > Dan > > > On Apr 29, 2022, at 2:46 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario - XML Security for Java > 2

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.4

2022-05-03 Thread Colm O hEigeartaigh
With 6 +1 votes, this vote passes. I'll do the release. Colm. On Mon, May 2, 2022 at 5:08 PM Daniel Kulp wrote: > > +1 > > Dan > > > On Apr 29, 2022, at 2:25 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Sanutario - XML Security for Java 2.2.4.

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.3.1

2022-05-03 Thread Colm O hEigeartaigh
With 7 binding +1 votes, this vote passes. I'll do the release. Colm. On Thu, Apr 28, 2022 at 1:20 PM Daniel Kulp wrote: > > +1 > > Dan > > > On Apr 28, 2022, at 4:18 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario - XML Security for J

Re: [VOTE] - Release Apache Santuario - XML Security for Java 3.0.0

2022-05-03 Thread Colm O hEigeartaigh
With 7 +1 votes, and no other votes, this vote passes. I'll do the release. Colm. On Thu, Apr 28, 2022 at 1:19 PM Daniel Kulp wrote: > > +1 > > Dan > > > On Apr 28, 2022, at 3:17 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario - XM

[VOTE] - Release Apache Santuario - XML Security for Java 2.2.4

2022-04-29 Thread Colm O hEigeartaigh
This is a vote to release Apache Sanutario - XML Security for Java 2.2.4. Issues fixed: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12350604 Git tag: https://github.com/apache/santuario-xml-security-java/tree/xmlsec-2.2.4 Artifacts:

[VOTE] - Release Apache Santuario - XML Security for Java 2.3.1

2022-04-28 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.3.1. Issues fixed: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12350855 Git tag: https://github.com/apache/santuario-xml-security-java/tree/xmlsec-2.3.1 Artifacts:

[VOTE] - Release Apache Santuario - XML Security for Java 3.0.0

2022-04-28 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 3.0.0. This is a new major release which has switched to use the Jakarta namespace. Issues fixed: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12351397 git tag:

Re: xmlsec with slf4j-api ?

2022-04-25 Thread Colm O hEigeartaigh
onfig.setXmlSecIgnoreLineBreak(WSSConfig.java:404) > at org.apache.ws.security.WSSConfig.init(WSSConfig.java:442) > at org.apache.ws.security.WSSConfig.getNewInstance(WSSConfig.java:486) > > --- > Thanks > Sateesh > > -Original Message- > From: Colm

Re: xmlsec with slf4j-api ?

2022-04-24 Thread Colm O hEigeartaigh
It's just an API jar, I believe you can use a NOPLogger if you don't want any logging (https://www.slf4j.org/api/org/slf4j/helpers/NOPLogger.html) Colm. On Thu, Apr 21, 2022 at 2:11 AM Sateesh K Kolusu wrote: > > > Hello - I have a question with usage of xmlsec-2.1.7.jar. I see >

Releases soon

2022-04-20 Thread Colm O hEigeartaigh
Hi, I'd like to call a vote soon on some new releases: - a new major release (3.0.0) that has switched to use the Jakarta bindings - New 2.2.x and 2.3.x releases - and the final release on the 2.1.x branch with a few minor fixes. Let me know if there are any thoughts or anything you want to

Re: Support for 2.1 branch / EOL?

2022-03-07 Thread Colm O hEigeartaigh
We're going to release 2.4.0 pretty soon, so ideally we would end it then. I recall though you asked for support until June or so, in which case we can extend it until then? Colm. On Fri, Mar 4, 2022 at 3:05 PM Cantor, Scott wrote: > > Was there a final decision made about support ending this

Re: [IMPORTANT] - ci.apache.org and CMS Shutdown end of January 2022

2022-02-01 Thread Colm O hEigeartaigh
Thanks Gavin, it seems everything is working correctly. Colm. On Thu, Jan 13, 2022 at 12:40 PM Gavin McDonald wrote: > > As per the update on the Jira ticket, I have a replacement script in place. > What I will do next is make a test edit to one of your wiki pages and see if > it publishes. >

Re: SANTUARIO-513 bug status

2022-01-19 Thread Colm O hEigeartaigh
Note, this comment only applies to the C++ library, not the Java library. Colm. On Wed, Jan 19, 2022 at 3:39 PM BEEK Graham wrote: > > Hi, > > > > This bug was raised 2 and a bit years ago and would seem quite important at > first glance, but there has been no activity. Would someone be able

Re: A jakarta namespace version

2021-12-02 Thread Colm O hEigeartaigh
If there is demand then I don't mind keeping 2.1.x for a while longer. It only gets security fixes anyway at this stage. Colm. On Thu, Dec 2, 2021 at 1:02 PM Cantor, Scott wrote: > > On 12/2/21, 5:16 AM, "Colm O hEigeartaigh" wrote: > > >The main reason is that we

Re: A jakarta namespace version

2021-12-02 Thread Colm O hEigeartaigh
Yes, good point. Colm. On Thu, Dec 2, 2021 at 10:26 AM Matti Aarnio wrote: > > Given that the Jakarta-namespace change is major incompatibility with > previous versions, > perhaps you should call it 3.0.0 ? > > Best Regards, > Matti > > On 02/12/2021 12.16

Re: A jakarta namespace version

2021-12-02 Thread Colm O hEigeartaigh
rovided for those who want to move now? > > On Mon, Nov 29, 2021 at 6:19 AM Colm O hEigeartaigh > wrote: >> >> We don't have an imminent release date yet, because the Santuario StAX >> implementation is really only used by Apache CXF, and CXF confirmed to >> me tha

Re: A jakarta namespace version

2021-11-29 Thread Colm O hEigeartaigh
When will this be available and in a public repository? > > On Tue, Nov 23, 2021 at 12:22 PM Colm O hEigeartaigh > wrote: >> >> Hi Rebecca, >> >> I believe we have an existing PR - >> https://github.com/apache/santuario-xml-security-java/pull/63 >> Or are you re

Re: A jakarta namespace version

2021-11-23 Thread Colm O hEigeartaigh
Hi Rebecca, I believe we have an existing PR - https://github.com/apache/santuario-xml-security-java/pull/63 Or are you referring to something else? Colm. On Tue, Nov 23, 2021 at 1:25 PM Rebecca Searls wrote: > > Wildfly components requires a jakarta namesapce version of >

Re: Santuario web site

2021-11-12 Thread Colm O hEigeartaigh
The website updates seem to be working again. Colm. On Fri, Nov 5, 2021 at 3:53 PM Cantor, Scott wrote: > > On 11/5/21, 11:34 AM, "Colm O hEigeartaigh" wrote: > > >Yes it appears that Infra have frozen publishing from SVN, so I will > >have to research a

Re: Santuario web site

2021-11-05 Thread Colm O hEigeartaigh
Yes it appears that Infra have frozen publishing from SVN, so I will have to research a different way of doing it from Git (I know Apache Directory made this change, so I hope it won't be too complicated). Colm. On Thu, Nov 4, 2021 at 2:27 PM Cantor, Scott wrote: > > I've never managed to get

Re: Proposed release of xml-security-c 2.0.4 - Call for Vote

2021-11-01 Thread Colm O hEigeartaigh
+1. Colm. On Mon, Nov 1, 2021 at 12:34 PM Daniel Kulp wrote: > > +1 > > Dan > > > On Nov 1, 2021, at 8:25 AM, Cantor, Scott wrote: > > I have posted a release candidate for 2.0.4 [1] to correct a regression on > OpenSSL 1.0.0 and older from the DSA bug fix included in the release last >

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.3.0

2021-11-01 Thread Colm O hEigeartaigh
With 4 binding +1 votes, this vote passes. Colm. On Mon, Oct 25, 2021 at 1:57 PM Sean Mullan wrote: > > +1 > > --Sean > > On 10/25/21 6:52 AM, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario - XML Security for Java > > 2.3.0. This is a ma

[VOTE] - Release Apache Santuario - XML Security for Java 2.3.0

2021-10-25 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.3.0. This is a major new release of the library. Some of the significant changes include: * A rewrite for the StAX output processor chain to make it deterministic - https://issues.apache.org/jira/browse/SANTUARIO-555 * Secure

[CVE-2021-40690] - Apache Santuario - XML Security for Java

2021-09-17 Thread Colm O hEigeartaigh
The Apache Santuario™ project is aimed at providing implementation of the primary security standards for XML: - XML-Signature Syntax and Processing - XML Encryption Syntax and Processing. A new CVE is released for Apache Santuario - XML Security for Java, which is fixed in the latest

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.1.7

2021-09-13 Thread Colm O hEigeartaigh
With 4 binding +1 votes this vote passes, I'll do the release Colm. On Fri, Sep 10, 2021 at 2:59 PM Colm O hEigeartaigh wrote: > > No, I need to increment the build number for the next release. > > Colm. > > On Fri, Sep 10, 2021 at 2:45 PM Cantor, Scott wrote: > >

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.3

2021-09-13 Thread Colm O hEigeartaigh
With 4 binding +1 votes this vote passes, I'll do the release Colm. On Fri, Sep 10, 2021 at 2:45 PM Cantor, Scott wrote: > > +1 > > -- Scott > >

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.1.7

2021-09-10 Thread Colm O hEigeartaigh
No, I need to increment the build number for the next release. Colm. On Fri, Sep 10, 2021 at 2:45 PM Cantor, Scott wrote: > > +1, assuming those Jenkins failures don't mean anything to do with this > release? > > -- Scott > >

[VOTE] - Release Apache Santuario - XML Security for Java 2.1.7

2021-09-10 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.1.7 Issues fixed: https://issues.apache.org/jira/projects/SANTUARIO/versions/12349490 Artifacts: https://repository.apache.org/content/repositories/orgapachesantuario-1031/ Git tag:

[VOTE] - Release Apache Santuario - XML Security for Java 2.2.3

2021-09-10 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.2.3. Issues fixed: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12350144 Artifacts: https://repository.apache.org/content/repositories/orgapachesantuario-1030/ Git tag:

Re: Regarding support of SHA224 as mgfalgorithm during encryption

2021-09-09 Thread Colm O hEigeartaigh
Will SHA224 be supported in > both cases? > - Construction of OAEPParameters in constructOAEPParameters method > - Construction of cipher using SHA224 digest algorithm in constructCipher > method > > Regards, > Sreenivas > > > On Wed 8 Sep, 2021, 4:2

Re: Regarding support of SHA224 as mgfalgorithm during encryption

2021-09-08 Thread Colm O hEigeartaigh
Hi, It will be fixed for the next release here - https://issues.apache.org/jira/browse/SANTUARIO-579 Colm. On Tue, Sep 7, 2021 at 11:48 PM Sreenivas Somavarapu wrote: > > Hi Team, > > > > Not sure if this is correct forum / mailing list to put this query. If this > is not could you let me

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.2

2021-05-04 Thread Colm O hEigeartaigh
With 4 binding +1 votes, and no other votes, this vote passes - I'll do the release. Colm. On Fri, Apr 30, 2021 at 5:33 PM Cantor, Scott wrote: > > +1 > > -- Scott > > On 4/30/21, 5:19 AM, "Colm O hEigeartaigh" wrote: > > This is a vote to release Apache

[VOTE] - Release Apache Santuario - XML Security for Java 2.2.2

2021-04-30 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.2.2. Artifacts: https://repository.apache.org/content/repositories/orgapachesantuario-1029/ Git tag: https://github.com/apache/santuario-xml-security-java/releases/tag/xmlsec-2.2.2 Issues fixed:

Release of 2.2.1 soon

2021-04-26 Thread Colm O hEigeartaigh
Hi all, I plan to call a vote on the 2.2.1 release this week, let me know if there are any last minute changes. Colm.

Re: Apache XML Security (xmlsec) for Java EOL versions?

2020-12-15 Thread Colm O hEigeartaigh
Hi, The current releases are 2.2.1 and 2.1.6 - the 2.2.x and 2.1.x branches are still supported. Anything before 2.1.x is EOL. As for dates, I would go with the JIRA releases page which lists the dates of each release:

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.1/2.1.6

2020-12-13 Thread Colm O hEigeartaigh
With 4 binding +1 votes, this vote passes - I'll do the release. Colm. On Tue, Dec 8, 2020 at 3:45 PM Daniel Kulp wrote: > +1 > > Dan > > > On Dec 8, 2020, at 7:40 AM, Colm O hEigeartaigh > wrote: > > This is a vote to release Apache Santuario - XML Security for

[VOTE] - Release Apache Santuario - XML Security for Java 2.2.1/2.1.6

2020-12-08 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.2.1/ 2.1.6. 2.2.1: Issues fixed: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12348362 Git tag: https://github.com/apache/santuario-xml-security-java/releases/tag/xmlsec-2.2.1 Artifacts:

Releases soon

2020-12-01 Thread Colm O hEigeartaigh
Hi all, I plan to call a vote on new 2.2.1 + 2.1.6 releases next week. Let me know if there is anything else that should go into these releases. Colm.

Re: method signature issue in xmlsec 2.2.0

2020-11-10 Thread Colm O hEigeartaigh
Hi, Answers inline. > I have been looking at upgrading our xmlsec dependency to 2.2.0, on the > basis that at some point the 2.1.x series will lose support. Is that > already the case? Not obvious from the web site at present. > It's not already the case, there will be at least a 2.1.6 release

Build Server moved

2020-07-23 Thread Colm O hEigeartaigh
Hi, The build server has migrated at Apache from Jenkins to CloudBees - the new build jobs for the Java project are here: https://ci-builds.apache.org/job/Santuario/ There are builds for the master branch using JDK8, 11 and 14. The JDK8 build also deploys SNAPSHOTS to

[ANNOUNCE] - Apache Santuario - XML Security for Java 2.2.0 released

2020-06-04 Thread Colm O hEigeartaigh
The Apache Santuario team announces the release of XML Security for Java 2.2.0. This is a new major release with the following features: - Added support for RSASSA-PSS with Parameters - Extensive refactoring and code simplification - JDK14 officially supported - Ability to set a

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.2.0

2020-06-04 Thread Colm O hEigeartaigh
With 4 binding +1 votes, this vote passes - I'll do the release. Colm. On Tue, May 26, 2020 at 2:13 PM Cantor, Scott wrote: > +1 > > -- Scott > > >

[VOTE] - Release Apache Santuario - XML Security for Java 2.2.0

2020-05-26 Thread Colm O hEigeartaigh
This is a vote to release Apache Santuario - XML Security for Java 2.2.0. This is a new major release with the following features: * Added support for RSASSA-PSS with Parameters * Extensive refactoring and code simplification * JDK14 officially supported * Ability to set a security provider

Source repository change for XML Security for Java

2020-05-18 Thread Colm O hEigeartaigh
Hi all, We have migrated the Apache Santuario - XML Security for Java project from SVN to GIT. Please update your local checkouts to either the gitbox or github repositories as listed on the website: http://santuario.apache.org/java-source-repository.html The old

Re: Release soon...

2020-04-03 Thread Colm O hEigeartaigh
I've completed the planned work for 2.2.0: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12344983 I hope to call a vote maybe in 3 weeks or so, so if there's anything else to go in please let me know. Colm. On Mon, Mar 2, 2020 at 3:37 PM Colm O hEigeartaigh wrote

Re: Created SANTUARIO-523 + pull request on GitHub - did I contribute correctly?

2020-01-31 Thread Colm O hEigeartaigh
Hi Peter, As Scott said, the github mirror is read-only at the moment, although we will move shortly to use git instead of svn. However if you prefer to submit pull requests to the mirror for now, I am OK with applying them manually. In terms of a next release, I want to get 2.1.5 out in a few

Moving to GIT

2020-01-14 Thread Colm O hEigeartaigh
Hi all, I want to switch the Apache Santuario XML Security for Java codebase to git at Apache (http://svn.apache.org/repos/asf/santuario/xml-security-java/). The website will stay on svn. I think Santuario is the last project at Apache I'm involved with that still uses svn. @Scott Cantor would

Re: CRLF change in Java 8 patch

2019-10-17 Thread Colm O hEigeartaigh
Hi Scott, Are you referring to the fix that was made for 2.1.2? https://issues.apache.org/jira/browse/SANTUARIO-482 As in, the latest Oracle patch, does not have this fix above? Colm. On Thu, Oct 17, 2019 at 3:16 PM Cantor, Scott wrote: > Sean, mostly: > > Were folks expecting to see Java 8

Re: [PATCH] RSASSA-PSS with Parameters

2019-09-11 Thread Colm O hEigeartaigh
Hi, Thanks for the patches - could you create a JIRA ( https://issues.apache.org/jira/projects/SANTUARIO) + attach the patches there? Colm. On Wed, Sep 11, 2019 at 9:04 AM Kunnar Klauks wrote: > Hello, > > Here is patch for supporting 'RSASSA-PSS with Parameters' as described in >

Re: [CVE-2019-12400] Apache Santuario potentially loads XML parsing code from an untrusted source

2019-09-06 Thread Colm O hEigeartaigh
Hi, Yes, Scott's interpretation is correct - I'm sorry if the wording of the CVE was not sufficiently clear. Let me see if there's a way to query the CVSSv3 score that was assigned to the CVE... Colm. On Fri, Sep 6, 2019 at 3:03 PM Cantor, Scott wrote: > On 9/6/19, 5:44 AM, "RvG" wrote: > >

[CVE-2019-12400] Apache Santuario potentially loads XML parsing code from an untrusted source

2019-08-23 Thread Colm O hEigeartaigh
, leading to potential security flaws when validating signed documents, etc. For more information, please see the security advisories page of Apache Santuario: http://santuario.apache.org/secadv.html -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.1.4

2019-07-20 Thread Colm O hEigeartaigh
With 5 +1 votes, including 3 binding +1 votes, this vote passes - I'll do the release. Colm. On Fri, Jul 19, 2019 at 12:59 PM Daniel Kulp wrote: > > +1 > > Dan > > > On 2019/07/16 15:59:03, Colm O hEigeartaigh wrote: > > This is a vote to release Apache Santuario -

Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.1.4

2019-07-16 Thread Colm O hEigeartaigh
ject our own via some kind of interface in a > future version? Or would a patch for that be welcome? > Yes I was thinking along those lines for 2.3.0. Patches definitely welcome! Colm. > > -- Scott > > > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

[VOTE] - Release Apache Santuario - XML Security for Java 2.1.4

2019-07-16 Thread Colm O hEigeartaigh
/repos/asf/santuario/xml-security-java/tags/xmlsec-2.1.4/ +1 from me. Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

[VOTE] - Release Apache Santuario - XML Security for Java 2.1.3

2019-03-26 Thread Colm O hEigeartaigh
://repository.apache.org/content/repositories/orgapachesantuario-1023/ +1 from me. Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: Java 2.1.3 release

2019-03-25 Thread Colm O hEigeartaigh
Thanks, this one should be viewable: https://issues.apache.org/jira/secure/ReleaseNote.jspa?projectId=12311231=12343431 Colm. On Mon, Mar 25, 2019 at 4:07 PM Cantor, Scott wrote: > On 3/22/19, 11:16 AM, "Colm O hEigeartaigh" wrote: > > > I'd like to get the Java 2.1.

Java 2.1.3 release

2019-03-22 Thread Colm O hEigeartaigh
Hi all, I'd like to get the Java 2.1.3 release out soon. We have seven issues fixed for it so far: https://issues.apache.org/jira/projects/SANTUARIO/versions/12343431 Anything else anyone wants to see in it? Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: xml-security-c 2.0.2 (call for vote)

2018-10-31 Thread Colm O hEigeartaigh
che.org/jira/browse/SANTUARIO-496 > [2] https://dist.apache.org/repos/dist/dev/santuario/c-library/ > > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: Digest Mismatch Exceptions and Enveloped Signatures

2018-07-27 Thread Colm O hEigeartaigh
> securityProperties.addSignaturePart(securePart); > }); > > > > > > Perhaps it would be helpful to include two separate examples, one using > stax signature verification with an enveloped signature and another one > with an enveloping signature? > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: Recovering XML Signature via JAXB

2018-07-20 Thread Colm O hEigeartaigh
t; > Any ideas here? Is this possible? Is there a test that shows how to use > the JAXB bindings? > > > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: Call for vote (#2): xml-security-c-2.0.0

2018-06-28 Thread Colm O hEigeartaigh
devote to > it unfortunately. > > It hasn't successfully published to the web yet but I'll keep an eye on it. > > -- Scott > > > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: Call for vote: xml-security-c-2.0.0

2018-06-22 Thread Colm O hEigeartaigh
ANGELOG is not updated for 2.0.0. > > I thought I had gutted that to not contain anything needing update but > I'll correct if not. I don't want to have to touch files like that when new > versions come out. > Yes my mistake, I missed the first sentence in it. Colm. > > -- Scott > > > > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

Re: Call for vote: xml-security-c-2.0.0

2018-06-22 Thread Colm O hEigeartaigh
et to include digests * The CHANGELOG is not updated for 2.0.0. Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com On Wed, Jun 20, 2018 at 5:54 PM, Cantor, Scott wrote: > I'd like to ask for a vote to release RC3, posted at [1], as the final > release

[VOTE] - Release Apache Santuario - XML Security for Java 2.1.2 (take III)

2018-06-08 Thread Colm O hEigeartaigh
://repository.apache.org/content/repositories/orgapachesantuario-1022/ +1 from me. Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

[CANCELLED] Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.0.11 (take II)

2018-06-08 Thread Colm O hEigeartaigh
release Apache Santuario - XML Security for Java > 2.0.11. > > > > +1 > > > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

[VOTE] - Release Apache Santuario - XML Security for Java 2.0.11 (take II)

2018-06-06 Thread Colm O hEigeartaigh
://repository.apache.org/content/repositories/orgapachesantuario-1021/ +1 from me. Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

[VOTE] - Release Apache Santuario - XML Security for Java 2.1.2 (take II)

2018-06-06 Thread Colm O hEigeartaigh
://repository.apache.org/content/repositories/orgapachesantuario-1020/ +1 from me. Colm. -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

[CANCEL] - Re: [VOTE] - Release Apache Santuario - XML Security for Java 2.0.11

2018-06-04 Thread Colm O hEigeartaigh
ty for Java >> 2.0.11. >> >> +1 >> >> -- Scott >> >> > -- Colm O hEigeartaigh Talend Community Coder http://coders.talend.com

  1   2   3   >