Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

SSP v2.5.2 General Release Announcement

Info

To Be Released in Mid-AugustSSP v2.5.2 released August 21, 2014

Release Highlights

 

Info

The release is primarily a patch set for bugs identified in v2.5.1.  Implementers are strongly encouraged to update to v2.5.2 to correct core functionality in Caseload and Search

...

Warning

It is important to first follow the steps in the Release Notes for v2.5.1 when upgrading to v2.5.2.

The SSP development team is not aware of any SSP deployments integrated with CAS, but this release includes two security-related patch sets specifically targeted at CAS integrations:

  • SSP-2721 - Scrubs certain CAS-specific request parameters. The changes and effects are detailed in the uPortal project.  No work should be required to enable the patch, but you may want to review that document to better understand the CAS-related configuration changes included in this release.
  • SSP-2724 - Works around what amounts to a CAS-specific session hijacking vulnerability. The changes and effects are detailed in the uPortal project and the <platform-src>/uportal-war/src/main/resources/properties/security.properties file includes greatly expanded comments describing recommended configuration changes. You will likely want to review the email thread and changes to that file whether or not you use CAS. The new defaults may interfere with your existing authentication provider integrations, especially AD/LDAP. SSP-specific details below.

1.  New permissions and functionality were created to remove the Main Tool from individual users or groups/role.  

...