Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Apache CXF Fediz is a subproject of CXF. Fediz helps you to secure your web applications and delegates security enforcement to the underlying application server. With Fediz, authentication is externalized from your web application to an identity provider installed as a dedicated server component. The supported standard is WS-Federation Passive Requestor Profile. Fediz supports Claims Based Access Control beyond Role Based Access Control (RBAC).

News

March 30September 8, 2016 - Apache CXF Fediz 1.3.0 .1 and 1.2.3 released

Apache CXF Fediz 1.3.0 has been released. It contains an update to use CXF 3.1 .6, a new OpenId Connect based IdP (Fediz OIDC), support for bridging between the WS-Federation and OpenId Connect protocols, and support for SAML SSO in the Fediz IdP.

For more information and to download the new releases, please go here.

February 16, 2016 - Apache CXF Fediz 1.2.2 released
Apache CXF Fediz 1.2.2 has been released. It contains an update to use CXF 3.0.8, some updates to the Websphere plugin, a fix for some issues relating to caching SAML tokens, and various other bug fixes.3 have been released.

For more information and to download the new releases, please go here.

August 28, 2015 September 8, 2016 - A new security advisory for Apache CXF Fediz is released

A security issue was fixed in the latest Fediz releases (1.23.1 + 1.12.3):

  • CVE-2015-5175: Apache CXF Fediz application plugins are vulnerable to Denial of Service (DoS) attacks

...