Metadata Aggregator - Issues with XMLSignatureSigningStage
Chad La Joie
lajoie at itumi.biz
Wed Nov 2 15:21:57 GMT 2011
Well, with the metadata aggregator we made our first move to using the
Java XML DSIG APIs. My initial guess is that the implementation that
ships with the JVM doesn't support anything but the what is explicitly
defined in the DSIG spec. I'll dig in to it a bit.
On Wed, Nov 2, 2011 at 11:04, Krug, Jeff <Jeff.Krug at gtri.gatech.edu> wrote:
> I did have one question regarding signing algorithm. Using the xmlsectool-1.1.4 I tweaked it to default to SHA256 signatures (and it uses Apache's digital signature classes to do this). This worked fine. The aggregator defaults to SHA256 (although conveniently configurable via a property) using the javax.crypto libraries, but for this I get the following error:
>
> 2011-11-02 10:52:30,398 - ERROR [net.shibboleth.metadata.dom.XMLSignatureSigningStage:644] - Unable to create signature method http://www.w3.org/2001/04/xmldsig-more#rsa-sha256
> java.security.NoSuchAlgorithmException: unsupported algorithm
> at org.jcp.xml.dsig.internal.dom.DOMXMLSignatureFactory.newSignatureMethod(Unknown Source) ~[na:1.6.0_16]
> at net.shibboleth.metadata.dom.XMLSignatureSigningStage.buildSignedInfo(XMLSignatureSigningStage.java:641) [aggregator-pipeline-0.6.1.jar:na]
>
> I can set it to use SHA1 via the property and it works fine, but I feel like there is something obvious I'm overlooking that needs to be done to support SHA256 (and better, the same type of error shows up for SHA384 and SHA512).
--
Chad La Joie
www.itumi.biz
trusted identities, delivered
More information about the dev
mailing list