RSA-OAEP vs. RSA-OAEP-MGF1P

Ian Young ian at iay.org.uk
Tue Feb 3 12:16:44 EST 2015


> On 3 Feb 2015, at 17:04, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
>> I checked the algorithm support spec before posting. I don't read it as
>> permitting that interpretation as it stands.
> 
> I'm still reading my code, but I think what I thought it meant was "any parameters are unspecified", so not exactly "all possibl parameters are supported".
> 
> So I apparently concluded that in practice, saying nothing would be as interoperable as listing all the digests since that doesn't mean "I don't support anything". It definitely doesn't mean that it only supports SHA-1.

In practice, though, what the IdP is interpreting it as meaning appears to be only MGF1 with SHA-1, which after all is what it means when you use it in the encryption context. So it's redundant as things stand.

I think I'd want a spec somewhere to say something specific about this before proposing that we change the IdP to assume it means the SP can handle other digest functions than SHA-1.

I posted a summary here:

https://issues.shibboleth.net/jira/browse/SSPCPP-642

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/dev/attachments/20150203/02e1d684/attachment.bin 


More information about the dev mailing list