Security defaults

Brent Putman putmanb at georgetown.edu
Sat May 17 23:37:16 EDT 2014


On 5/17/14 4:49 PM, Cantor, Scott wrote:
> We blacklist it now in the SP. We don't have a lot of decryption use cases
> in the IdP, but we should be consistent.

I thought we were actually talking about encryption, since that's where
it's enumerated right now.  There aren't algorithm lists for decryption
(and validation), just whitelists and blacklists.  I would assume that
if we're going to blacklist RSA 1.5, we'd do it for for both encryption
and decryption (just like you see right now for MD5, for both signing
and validation).






More information about the dev mailing list