<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="putmanb@shibboleth.net" id="email_putmanb@shibboleth.net" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=putmanb%40shibboleth.net" style="color:#326ca6;">Brent Putman</a>
edited a comment on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/task.png" height="16" width="16" border="0" align="absmiddle" alt="Task"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-64'>OSJ-64</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/OSJ-64'><strong>Support algorithm whitelisting and blacklisting for decryption and signature validation operations</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>Extracted out a new SignaturePrevalidator interface from the SAML profile validator. </p>
<p>Created a new impl of that called SignatureAlgorithmValidator for doing algorithm whitelist/blacklist eval on a Signature. So that aspect is pretty much done.</p>
<p>What is TBD is where/how this algorithm validator actually gets called. I see 2 options so far:</p>
<p>1) The component that is going to do signature eval via a SignatureTrustEngine first invokes the algorithm validator (so prior to the trust engine). Constructs validator dynamically if necessary (see metadata filter case below). Use the data available to it at runtime (SignatureValidationParameters or raw whitelist/blacklist collections).</p>
<p>2) Instead have that component pass the SignatureValidationParameters or raw whitelist/blacklist data to the SignatureTrustEngine as a Criterion. SignatureTrustEngine impl creates a SignatureAlgorithmValidator using that data and executes.</p>
<p>Each has upsides and downsides.</p>
<p>The metadata filter case is a little different, b/c the data isn't dynamic at runtime. So either A) the SignatureValidationParameters or whitelist/blacklist data could be wired into it statically, and it operates as above, else or B) it could be injected with the prevalidator containing that data. If the latter, then would actually be a ChainingSignaturePrevalidtor containing (at a minimum) the SAMLSignatureProfileValidator and SignatureAlgorithmValidator.</p></div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->