Hej på er alla!
Välkomna tillbaka efter sommaren. Jag hoppas att ni blivit uppvilade.
Som ni vet gjorde vi en större uppdatering av tillitsprofilerna under 2020 samt två mindre 2024 och 2025. Baserat på dessa uppdateringar behöver nedanstående organisationer uppdatera sina Identity Management Practice Statement (IMPS). VI skickar ut detta informationsbrev så att ni kan genomföra uppdateringarna planerat. Finns er organisation inte nämnd nedan behöver ni inte göra någon uppdatering.
Om ni har några frågor och funderingar hör av er till operations(a)swamid.se<mailto:operations@swamid.se>. Om ni ser ett behov tar Swamid Operations gärna ett eller flera möten med er för att stödja er i uppdateringsprocessen.
Organisationer som blivit godkända före 2021 - Akuta åtgärder krävs snarast!
Organisationer som berörs av förändringarna och behöver uppdatera och bli godkända av Swamid Board of Trustees senast oktober 2026:
* Gymnastik- och idrottshögskolan [pågår]
* Högskolan i Gävle [pågår]
* Naturhistoriska riksmuséet [pågår]
* Universitetskanslersämbetet [pågår]
* Forskningsrådet Formas
* Forskningsrådet Forte
* Klimatpolitiska rådet
* Rymdstyrelsen
* Stiftelsen för strategisk forskning
Förändringen 2020 var väldigt omfattande och därför behövs en omfattande genomgång och uppdatering av IMPSen genomföras snarast baserat på aktuell version av tillitsprofilerna. Denna uppdatering måste beslutas av Swamid Board of Trustees på nästa möte. Om detta inte sker kommer identitetsutgivaren för organisationen att tillfälligt stängas av från Swamid fram till att uppdateringen av IMPSen är godkänd.
Organisationer som blivit godkända 2021-2024
Organisationer som berörs av förändringarna och behöver uppdatera senast vid årliga validering under 2026:
* Försvarshögskolan
* Högskolan Väst
* Kungliga Vetenskapsakademien
* Kungliga biblioteket
* Lunds universitet [pågår]
* Marie Cederschiöld högskola
* NORDUnet
* Sophiahemmet Högskola
* Universitets- och högskolerådet
* Universitets- och högskolerådet - Antagning.se
* Vetenskapsrådet
* World Maritimae University
Organisationer som berörs av förändringarna och behöver uppdatera senast vid årlig validering under 2027:
* Chalmers tekniska högskola
* Högskolan Dalarna
* Högskolan Kristianstad [pågår]
* Högskolan i Halmstad
* Högskolan i Skövde [pågår]
* Karolinska institutet
* Konstfack
* Kungliga Konsthögskolan
* Kungliga tekniska högskolan
* Luleå tekniska universitet [pågår]
* Malmö universitet [pågår]
* Mittuniversitetet [pågår]
* Röda Korsets Högskola
* Stockholms konstnärliga högskola
* Stockholms universitet
* Vetenskapsrådet - SUNET
* Vetenskapsrådet - eduID
* Örebro universitet
Uppdateringarna som beslutades innehöll inga funktionella skillnader utan tillitsprofilerna strukturerades om för att bli tydligare gällande krav vilket medför förändrade krav hur tillitsprofilen skrivs. Detta betyder att ett antal avsnitt behöver förändras antingen genom att flytta text från ett avsnitt till ett annat eller utökad skrivning för tydlighet. Sektion 4.5.1 angående incidenthantering tillkom men detta krav finns redan tidigare i teknologiprofilen för SAML så kravet är inte nytt. Ändringarna finns i spårbart skick publicerad på https://wiki.sunet.se/spaces/SWAMID/pages/214570868/%C3%96versyn+av+SWAMIDs….
Uppdateringen som beslutades i december 2025 gällde primärt att NIST släppte en ny version av NIST Special Publication 800-63 Digital Identity Guidelines. Denna används i sektion 5.1.1 i tillitsprofilerna för att beskriva autentiseringsmodeller som är godkända inom aktuell tillitsprofil. NIST bytta namn på modellerna och därför behövde en mindre konsekvensuppdatering genomföras. Samtidigt passade vi på att dela avsnitt 4.4.1 gällande loggning i två sektioner, 4.4.1 och 4.4.2. Förändringarna runt 4.4.1 är samma i alla tillitsprofilerna. Ändringen finns i spårbart skick publicerad på https://wiki.sunet.se/spaces/SWAMID/pages/284459423/%C3%96versyn+av+Swamids….
Organisationer som blivit godkända efter 2024
Uppdateringen som beslutades i december 2025 gällde primärt att NIST släppte en ny version av NIST Special Publication 800-63 Digital Identity Guidelines. Denna används i sektion 5.1.1 i tillitsprofilerna för att beskriva autentiseringsmodeller som är godkända inom aktuell tillitsprofil. NIST bytta namn på modellerna och därför behövde en mindre konsekvensuppdatering genomföras. Samtidigt passade vi på att dela avsnitt 4.4.1 gällande loggning i två sektioner, 4.4.1 och 4.4.2. Funktionellt är uppdateringen så liten att ingen uppdatering av er IMPS behöver göras.
Swamid Operations genom
Pål Axelsson
Hej!
Enligt SWAMID SAML WebSSO Technology Profile (3.2 och 3.3) ska en entitet årligen bekräfta att den uppfyller teknologi-profilen.
Följande entiteter har trots påtryckning inte bekräftats och kommer därför raderas på datum nedan.
Vet ni med er att entiteten används vid ert lärosäte behöver ni skyndsamt eskalera detta till rätt instans inom er organisation.
Raderas 2026-08-19:
https://client200-179.its.umu.se/shibbolethhttps://test-isp.sae.kau.se/isptest
Det går att följa status på dessa entiteter via vår felsida:
https://metadata.swamid.se/admin/?action=ErrorList
Finns entiteten kvar är den ännu inte hanterad (uppdateras varje onsdag morgon). Last
Confirmed/Validated uppdateras dock löpande.
--
jocar
SWAMID Operations
Hej.
För kännedom.
// Björn M.
> Begin forwarded message:
>
> From: Henri Mikkonen <henri.mikkonen(a)nimbleidm.com>
> Subject: OIDC OP v4.3.1 now available
> Date: 14 July 2026 at 11:55:15 CEST
> To: announce(a)shibboleth.net
> Reply-To: users(a)shibboleth.net
>
> The Shibboleth Project has released V4.3.1 of the OIDC OP plugin (see release notes at [1])
>
> This is a patch release addressing bugs with RP-initiated logout, dynamic client registration and LDAP-wiring to the OAuth2 client authentication flow.
>
> -- Henri Mikkonen, on behalf of the team
>
> [1] https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/2776760321/OP…
> --
> To unsubscribe from this list send an email to announce-unsubscribe(a)shibboleth.net
För kännedom.
> Begin forwarded message:
>
> From: Scott Cantor via announce <announce(a)shibboleth.net>
> Subject: Shibboleth Identity Provider V5.2.3 now available
> Date: 18 June 2026 at 15:02:50 GMT+2
>
> The Shibboleth Project has released a patch version of the IdP software to refresh a number of libraries with open CVEs, including Spring, which announced a large number of them last week, as well as ldaptive/netty and logback (which had gotten pretty out of date).
>
> We don't think any of them were all that impactful if at all, but releasing was much less work than a detailed triage of everything.
>
> For Jetty plugin adopters, it looks as though the logging libraries are not (yet) getting updated inside the Jetty plugin configuration the way we expected, so that's something we'll check into and get fixed, it can be done manually for the moment.
>
> -- Scott
>
Hej!
Enligt SWAMID SAML WebSSO Technology Profile (3.2, 3.3 och 6.6.2) ska en entitet årligen bekräfta
att den uppfyller teknologi-profilen samt ha tidsmässigt giltigt certifikat.
Följande entiteter har trots påtryckning inte bekräftats eller har ett certifikat som gått ut och kommer därför raderas 2026-06-24 ur federationen.
* https://systest.stipendierauk.uhr.se/shibboleth <https://metadata.swamid.se/admin/?showEntity=5863>
Vet ni med er att entiteten används vid ert lärosäte behöver ni skyndsamt eskalera detta
till rätt instans inom er organisation.
Det går att följa status på dessa entiteter via vår felsida:
https://metadata.swamid.se/admin/?action=ErrorList
Finns entiteten kvar är den ännu inte hanterad (uppdateras varje onsdag morgon). Last
Confirmed/Validated uppdateras dock löpande.
--
jocar
Swamid Operations
Hej,
Igår den 25 maj höll Swamid Board of Trustees sitt första möte för 2026 och protokollet finns publicerat på https://wiki.sunet.se/spaces/SWAMID/pages/318701630/SWAMID+BoT+2026-05-25.
Att notera från mötet är att två nya lärosäten blev godkända för Swamid AL3 och att ytterligare fem fick uppdaterade Swamid AL2 godkända.
Vidare så beslutades att det organisationer som ännu inte blivit färdiga med uppdatering av sina Identity Management Practice Statement och blivit godkända före uppdateringen av tillitsprofilerna 2020 måste slutföra denna uppdatering före 31 oktober, annars blir de avstängda från Swamid tills uppdatering slutförd.
Pål Axelsson
FYI
// Björn M.
> Begin forwarded message:
>
> From: Philip Smart via announce <announce(a)shibboleth.net>
> Subject: WebAuthn plugin V1.4.2 now available
> Date: 20 May 2026 at 11:55:46 GMT+2
> To: "announce(a)shibboleth.net" <announce(a)shibboleth.net>
> Cc: Philip Smart <Philip.Smart(a)jisc.ac.uk>
> Reply-To: users(a)shibboleth.net
>
> The Shibboleth Project has released version 1.4.2 of the WebAuthn authentication plugin.
>
> This patch release primarily updates the Yubico WebAuthn libraries to version 2.9.0, including a fix for a FIDO metadata parsing issue.
>
> Version 2.9.0 also resolves a regression we identified and reported in later releases of the Yubico library, which led to a high-severity impersonation vulnerability [1]. We were not affected by this issue and intentionally deferred upgrading until a fix was available.
>
> For full details, please refer to the release notes [2].
>
> — Phil Smart, on behalf of the team
>
> [1] https://www.yubico.com/support/security-advisories/ysa-2026-02/
> [2] https://shibboleth.atlassian.net/wiki/spaces/IDPPLUGINS/pages/3394928781/We…
>
>
> Jisc is a registered charity (in England and Wales under charity number 1149740; in Scotland under charity number SC053607) and a company limited by guarantee registered in England under company number 05747339, VAT number GB 197 0632 86. Jisc's registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
>
>
> Jisc Services Limited is a wholly owned Jisc subsidiary and a company limited by guarantee which is registered in England under company number 02881024, VAT number GB 197 0632 86. The registered office is: 4 Portwall Lane, Bristol, BS1 6NB. T 0203 697 5800.
>
>
> For more details on how Jisc handles your data see our privacy notice here: https://www.jisc.ac.uk/website/privacy-notice
>
> --
> To unsubscribe from this list send an email to announce-unsubscribe(a)shibboleth.net <mailto:announce-unsubscribe@shibboleth.net>
Uppdateringen av Shibboleth som kom förra veckan var ett par viktiga säkerhetsuppdateringar och det är rekommenderat att uppdatera så snart som möjligt.
Pål
> -----Original Message-----
> From: announce <announce-bounces(a)shibboleth.net> On Behalf Of Scott Cantor
> via announce
> Sent: Wednesday, May 13, 2026 10:08 PM
> To: announce(a)shibboleth.net
> Cc: Scott Cantor <scott(a)restingparrotsoftware.com>
> Subject: Shibboleth Identity Provider Security Advisory [13 May 2026]
>
> Shibboleth Identity Provider Security Advisory [13 May 2026]
>
> An updated version of the Identity Provider software is available
> which includes explicit features and updated defaults to correct
> a denial of service vulnerability that can cause unconstrained
> resource consumption using XML that exceeds typical limits on
> certain kinds of content.
>
> Updates to OpenSAML are included in this patch, but this advisory
> refers to the specific impact and mitigations for the IdP itself.
>
> A separate advisory is available for OpenSAML alone.
>
> Maliciously crafted XML causes excessive resource consumption
> =============================================================
> While the XML parser in newer versions of Java includes default
> settings that limit certain kinds of malicious content, older
> versions did not and so can be vulnerable to specially crafted
> XML. These default settings are in any case not set low enough
> to be safe in this usage context.
>
> The OpenSAML library's decoding of SAML and SOAP messages is
> unprotected in its default configuration from such content and
> parsing some messages can result in memory and/or CPU exhaustion,
> causing a denial of service in applications using it, including
> the Shibboleth Identity Provider.
>
> Since most XML message types are parsed either without the
> protection of a signature or in advance of evaluating one, the
> exploit does not require an authenticated attacker and so is
> serious, though as a denial of service issue it remains in a
> lower tier of vulnerabilities.
>
> An updated version of the IdP (V5.2.2) is available which
> add new properties that limit parsing of most content that could
> expose the system to attack:
>
> * idp.xml.elementAttributeLimit (default 30)
> * idp.xml.maxElementDepth (default 25)
>
> In addition, the IdP now uses distinct parser settings when parsing
> SAML Metadata that are less strict than those used in general or
> messaging scenarios (and can be independently controlled). This
> allows for unusually crafted Metadata that has been observed in the
> wild by our community.
>
> Finally, the IdP has been enhanced with several new properties that
> can be set to control the size limits on various types of SAML and
> SOAP messages being decoded. Those limits are not enabled by default,
> but are supported in case they are needed in the future.
>
> See also the Releases Notes [1] and documentation [2].
>
> Recommendations
> ===============
> Update to V5.2.2 (or later) of the Identity Provider software. The
> updated default settings are deemed sufficiently safe at this time.
>
> In the event that upgrading is not possible, in most older versions
> one may directly configure new parser attributes directly by overriding
> the Spring bean used to control the parsing performed in most (but
> not all) cases.
>
> To do so, define a bean like so in conf/global.xml:
>
> <bean id="custom.ParserPool" parent="shibboleth.DefaultParserPool">
> <property name="builderAttributes">
> <map>
> <entry key="jdk.xml.elementAttributeLimit" value="30" />
> <entry key="jdk.xml.maxElementDepth" value="25" />
> </map>
> </property>
> </bean>
>
> Then add a property to conf/idp.properties:
>
> idp.xml.parserPool = custom.ParserPool
>
> This is not a foolproof solution for various reasons, but it mitigates
> the most common attack vectors.
>
> Note that we do not know the specific older versions of Java that
> support these parser attributes, and they are known to have gone by
> different names in some older versions prior to Java 17. If you are
> on an unsupported, older version, refer to the relevant JAXP parser
> documentation in that Java version for details.
>
> Credits
> =======
> Jens Friess and Haya Schulmann, Goethe University Frankfurt.
>
>
> [1] https://shibboleth.atlassian.net/wiki/x/T4C0vg
> [2] https://shibboleth.atlassian.net/wiki/x/AQDJPQE
>
> URL for this Security Advisory:
> https://shibboleth.net/community/advisories/secadv_20260513.txt
> -----Original Message-----
> From: announce <announce-bounces(a)shibboleth.net> On Behalf Of Scott Cantor
> via announce
> Sent: Tuesday, May 12, 2026 8:54 PM
> To: announce(a)shibboleth.net
> Cc: Scott Cantor <scott(a)restingparrotsoftware.com>
> Subject: Shibboleth Jetty plugin updated (V1.0.1)
>
> I wouldn't normally make much of an announcement, but...there's an unfortunate
> logging issue in the command line code in the original Jetty plugin that
> interacts..."badly" with the upcoming IdP patch that's due shortly, so I
> accelerated a patch release of the plugin to correct that issue before the IdP
> lands.
>
> 1.0.1 is out there now.
>
> If you're using the Jetty plugin, I'd advise getting that updated first, or at least be
> aware if you run a Jetty download with the old version and the new IdP...it will be
> very slow and ugly, logging every byte the HTTP client sees.
>
> There are a few other very small bug fixes in it, but that's the only significant
> thing.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to announce-
> unsubscribe(a)shibboleth.net
Uppdateringen av Shibboleth som kom förra veckan var ett par viktiga säkerhetsuppdateringar och det är rekommenderat att uppdatera så snart som möjligt.
Pål
> -----Original Message-----
> From: announce <announce-bounces(a)shibboleth.net> On Behalf Of Scott Cantor
> via announce
> Sent: Wednesday, May 13, 2026 10:09 PM
> To: announce(a)shibboleth.net
> Cc: Scott Cantor <scott(a)restingparrotsoftware.com>
> Subject: OpenSAML Security Advisory [13 May 2026]
>
> OpenSAML Security Advisory [13 May 2026]
>
> An updated version of the OpenSAML Java library is available
> which includes explicit features and updated defaults to correct
> a denial of service vulnerability that can cause unconstrained
> resource consumption using XML that exceeds typical limits on
> certain kinds of content.
>
> Maliciously crafted XML causes excessive resource consumption
> =============================================================
> While the XML parser in newer versions of Java includes default
> settings that limit certain kinds of malicious content, older
> versions did not and so can be vulnerable to specially crafted
> XML. These default settings are in any case not set low enough
> to be safe in this usage context.
>
> The OpenSAML library's decoding of SAML and SOAP messages is
> unprotected in its default configuration from such content and
> parsing some messages can result in memory and/or CPU exhaustion,
> causing a denial of service in applications using it.
>
> Most/all applications using OpenSAML to parse SAML messages may
> be vulnerable to this issue.
>
> Since most XML message types are parsed either without the
> protection of a signature or in advance of evaluating one, the
> exploit does not require an authenticated attacker and so is
> serious, though as a denial of service issue it remains in a
> lower tier of vulnerabilities.
>
> An updated versions of the OpenSAML Java library (V5.2.2) is
> available which establish new defaults for these two parser
> settings when using the OpenSAML internal ParserPool instance:
>
> * jdk.xml.elementAttributeLimit (default 30)
> * jdk.xml.maxElementDepth (default 25)
>
> These properties are supported by Java 17 and later, the minimum
> Java version supported by the library. We believe the parser
> properties alone are sufficient at present to mitigate this issue.
>
> However, note that *only* the ParserPool object installed into
> the OpenSAML library configuration is configured with these settings.
> If your application does its own XML parsing, then you are *not*
> protected and are vulnerable to this and many other security risks
> that you are solely responsible for mitigating. This is something
> we strongly advise against doing.
>
> In addition, the library has been enhanced with several new options
> that can be set to control the size limits on various types of SAML
> and SOAP messages being decoded. Those options are not enabled by
> default, but are present in case they are needed in the future.
>
> Recommendations
> ===============
> Update to V5.2.2 of the library. The updated default settings on the
> internally configured ParserPool are deemed sufficiently safe at this
> time, but *only* under the assumption that the library's ParserPool
> instance is always used.
>
> Another mitigation if our ParserPool is not used is to directly configure
> size limits on the MessageDecoder classes in use, but we have not explored
> the efficacy of this approach.
>
> In the event that upgrading is not possible, for this immediate issue
> one can set the two properties noted above as system properties on the
> command line (typically via a -D<option>=value addition to the
> relevant process' startup command).
>
> Note that this will impact all uses of JAXP in the process globally,
> which can of course create problems when parsing other content that
> might be expected to exceed limits.
>
> Note also that we do not know the specific older versions of Java that
> support these parser attributes, and they are known to have gone by
> different names in some older versions prior to Java 17. If you are
> on an unsupported, older version, refer to the relevant JAXP parser
> documentation in that Java version for details.
>
> Credits
> =======
> Jens Friess and Haya Schulmann, Goethe University Frankfurt.
>
>
> URL for this Security Advisory:
> https://shibboleth.net/community/advisories/secadv_20260513a.txt