Uploaded image for project: 'Apache NiFi'
  1. Apache NiFi
  2. NIFI-8186

Exclude bcprov-ext-jdk15on from spring-security-saml2-core

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 1.13.0
    • 1.13.0
    • None

    Description

      The spring-security-saml2-core library has a transitive dependency on bcprov-ext-jdk15on version 1.60 through the com.narupley:not-going-to-be-commons-ssl library.  The standard bcprov-jdk15on library is configured with version 1.68 through the framework, so the older extension version of the Bouncy Castle Provider should be excluded to avoid expected runtime behavior.  The standard and extended versions of the Bouncy Castle Provider libraries are fundamentally similar, with the primary difference being the inclusion of classes to support of obscure NTRU algorithm in the extension library.

      Attachments

        Issue Links

          Activity

            People

              exceptionfactory David Handermann
              exceptionfactory David Handermann
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - Not Specified
                  Not Specified
                  Remaining:
                  Remaining Estimate - 0h
                  0h
                  Logged:
                  Time Spent - 0.5h
                  0.5h