- Issued:
- 2014-10-13
- Updated:
- 2014-10-13
RHEA-2014:1514 - new packages: xmlsec1, lasso, mod_auth_mellon
Synopsis
new packages: xmlsec1, lasso, mod_auth_mellon
Type/Severity
Product Enhancement Advisory (none)
Topic
New xmlsec1, lasso, mod_auth_mellon packages are now available for Red Hat Enterprise Linux 6.
Description
The mod_auth_mellon packages provide the mod_auth_mellon module that is an authentication service implementing the Security Assertion Markup Language (SAML) federation protocol version 2.0. It grants access based on the attributes received in assertions generated by an IDP server.
The lasso packages provide the Lasso library that implements the Liberty Alliance Single Sign On standards, including the SAML and SAML2 specifications. It allows handling of the whole life-cycle of SAML-based federations, and provides bindings for multiple languages.
The xmlsec1 packages provide XML Security Library, a C library based on LibXML2 and OpenSSL. The library was created with a goal to support major XML security standards "XML Digital Signature" and "XML Encryption".
This enhancement update adds the xmlsec1, lasso, and mod_auth_mellon packages to Red Hat Enterprise Linux 6 in order to provide SAML Service Provider support in the Apache HTTP server. (BZ#1083605, BZ#1087555, BZ#1090812)
All users who require support for SAML-based federations in the Apache HTTP server are advised to install these new packages.
Solution
Before applying this update, make sure all previously released errata relevant to your system have been applied.
This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258
Affected Products
| Product | Version | Arch |
|---|---|---|
| Red Hat Enterprise Linux for Power, big endian | 6 | ppc64 |
| Red Hat Enterprise Linux for IBM z Systems | 6 | s390x |
| Red Hat Enterprise Linux Workstation | 6 | x86_64 |
| Red Hat Enterprise Linux Workstation | 6 | i386 |
| Red Hat Enterprise Linux Server | 6 | x86_64 |
| Red Hat Enterprise Linux Server | 6 | i386 |
| Red Hat Enterprise Linux Server from RHUI | 6 | x86_64 |
| Red Hat Enterprise Linux Server from RHUI | 6 | i386 |
| Red Hat Enterprise Linux Server - Retired Extended Life Cycle Support | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | x86_64 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension | 6 | i386 |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) | 6 | s390x |
| Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) | 6 | s390x |
Updated Packages
- lasso-debuginfo-2.4.0-5.el6.s390x.rpm
- xmlsec1-gnutls-1.2.20-4.el6.s390x.rpm
- mod_auth_mellon-0.8.0-2.el6.ppc64.rpm
- xmlsec1-1.2.20-4.el6.s390x.rpm
- xmlsec1-openssl-devel-1.2.20-4.el6.i686.rpm
- xmlsec1-devel-1.2.20-4.el6.x86_64.rpm
- mod_auth_mellon-debuginfo-0.8.0-2.el6.x86_64.rpm
- xmlsec1-1.2.20-4.el6.s390.rpm
- xmlsec1-gnutls-devel-1.2.20-4.el6.s390.rpm
- xmlsec1-gcrypt-1.2.20-4.el6.i686.rpm
- xmlsec1-nss-devel-1.2.20-4.el6.ppc64.rpm
- mod_auth_mellon-debuginfo-0.8.0-2.el6.i686.rpm
- xmlsec1-gcrypt-devel-1.2.20-4.el6.x86_64.rpm
- lasso-python-2.4.0-5.el6.s390x.rpm
- xmlsec1-gnutls-1.2.20-4.el6.x86_64.rpm
- lasso-python-2.4.0-5.el6.i686.rpm
- lasso-debuginfo-2.4.0-5.el6.ppc64.rpm
- xmlsec1-1.2.20-4.el6.i686.rpm
- xmlsec1-devel-1.2.20-4.el6.s390.rpm
- lasso-debuginfo-2.4.0-5.el6.ppc.rpm
- xmlsec1-1.2.20-4.el6.src.rpm
- xmlsec1-openssl-devel-1.2.20-4.el6.ppc.rpm
- lasso-2.4.0-5.el6.ppc64.rpm
- xmlsec1-devel-1.2.20-4.el6.ppc64.rpm
- lasso-python-2.4.0-5.el6.x86_64.rpm
- lasso-2.4.0-5.el6.s390x.rpm
- xmlsec1-gcrypt-devel-1.2.20-4.el6.ppc.rpm
- xmlsec1-gcrypt-1.2.20-4.el6.ppc.rpm
- xmlsec1-nss-1.2.20-4.el6.ppc.rpm
- xmlsec1-debuginfo-1.2.20-4.el6.ppc64.rpm
- xmlsec1-devel-1.2.20-4.el6.s390x.rpm
- xmlsec1-openssl-devel-1.2.20-4.el6.ppc64.rpm
- lasso-2.4.0-5.el6.ppc.rpm
- xmlsec1-openssl-1.2.20-4.el6.ppc.rpm
- xmlsec1-openssl-1.2.20-4.el6.s390.rpm
- lasso-devel-2.4.0-5.el6.i686.rpm
- xmlsec1-debuginfo-1.2.20-4.el6.s390x.rpm
- xmlsec1-gcrypt-devel-1.2.20-4.el6.i686.rpm
- xmlsec1-nss-1.2.20-4.el6.i686.rpm
- xmlsec1-gnutls-devel-1.2.20-4.el6.i686.rpm
- lasso-2.4.0-5.el6.src.rpm
- xmlsec1-gnutls-1.2.20-4.el6.ppc.rpm
- xmlsec1-gnutls-1.2.20-4.el6.i686.rpm
- xmlsec1-gcrypt-1.2.20-4.el6.s390x.rpm
- lasso-2.4.0-5.el6.s390.rpm
- xmlsec1-openssl-devel-1.2.20-4.el6.s390x.rpm
- xmlsec1-1.2.20-4.el6.ppc64.rpm
- xmlsec1-openssl-devel-1.2.20-4.el6.s390.rpm
- xmlsec1-gcrypt-devel-1.2.20-4.el6.ppc64.rpm
- mod_auth_mellon-0.8.0-2.el6.x86_64.rpm
- xmlsec1-nss-1.2.20-4.el6.s390.rpm
- lasso-devel-2.4.0-5.el6.ppc64.rpm
- lasso-devel-2.4.0-5.el6.ppc.rpm
- xmlsec1-gnutls-devel-1.2.20-4.el6.ppc.rpm
- xmlsec1-nss-1.2.20-4.el6.s390x.rpm
- xmlsec1-debuginfo-1.2.20-4.el6.ppc.rpm
- lasso-devel-2.4.0-5.el6.s390x.rpm
- xmlsec1-gnutls-1.2.20-4.el6.s390.rpm
- xmlsec1-gcrypt-devel-1.2.20-4.el6.s390x.rpm
- xmlsec1-1.2.20-4.el6.x86_64.rpm
- lasso-devel-2.4.0-5.el6.s390.rpm
- xmlsec1-gcrypt-1.2.20-4.el6.x86_64.rpm
- xmlsec1-openssl-1.2.20-4.el6.i686.rpm
- xmlsec1-devel-1.2.20-4.el6.i686.rpm
- mod_auth_mellon-0.8.0-2.el6.s390x.rpm
- xmlsec1-openssl-devel-1.2.20-4.el6.x86_64.rpm
- xmlsec1-gnutls-devel-1.2.20-4.el6.x86_64.rpm
- xmlsec1-gcrypt-devel-1.2.20-4.el6.s390.rpm
- xmlsec1-nss-devel-1.2.20-4.el6.x86_64.rpm
- mod_auth_mellon-0.8.0-2.el6.src.rpm
- lasso-debuginfo-2.4.0-5.el6.i686.rpm
- mod_auth_mellon-debuginfo-0.8.0-2.el6.s390x.rpm
- xmlsec1-debuginfo-1.2.20-4.el6.i686.rpm
- lasso-devel-2.4.0-5.el6.x86_64.rpm
- xmlsec1-gnutls-devel-1.2.20-4.el6.s390x.rpm
- xmlsec1-debuginfo-1.2.20-4.el6.x86_64.rpm
- xmlsec1-gnutls-1.2.20-4.el6.ppc64.rpm
- lasso-debuginfo-2.4.0-5.el6.x86_64.rpm
- xmlsec1-nss-devel-1.2.20-4.el6.s390x.rpm
- xmlsec1-openssl-1.2.20-4.el6.ppc64.rpm
- lasso-2.4.0-5.el6.i686.rpm
- xmlsec1-nss-1.2.20-4.el6.ppc64.rpm
- mod_auth_mellon-0.8.0-2.el6.i686.rpm
- mod_auth_mellon-debuginfo-0.8.0-2.el6.ppc64.rpm
- xmlsec1-gcrypt-1.2.20-4.el6.s390.rpm
- xmlsec1-openssl-1.2.20-4.el6.s390x.rpm
- xmlsec1-nss-devel-1.2.20-4.el6.ppc.rpm
- xmlsec1-devel-1.2.20-4.el6.ppc.rpm
- xmlsec1-gcrypt-1.2.20-4.el6.ppc64.rpm
- xmlsec1-gnutls-devel-1.2.20-4.el6.ppc64.rpm
- xmlsec1-nss-devel-1.2.20-4.el6.s390.rpm
- xmlsec1-nss-devel-1.2.20-4.el6.i686.rpm
- xmlsec1-nss-1.2.20-4.el6.x86_64.rpm
- lasso-2.4.0-5.el6.x86_64.rpm
- xmlsec1-openssl-1.2.20-4.el6.x86_64.rpm
- xmlsec1-1.2.20-4.el6.ppc.rpm
- lasso-python-2.4.0-5.el6.ppc64.rpm
- lasso-debuginfo-2.4.0-5.el6.s390.rpm
- xmlsec1-debuginfo-1.2.20-4.el6.s390.rpm
Fixes
CVEs
(none)
References
(none)
Additional information
- The Red Hat security contact is This content is not included.secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.
- Offline Security Data data is available for integration with other systems. See Offline Security Data API to get started.