Signature-limitations on HTTPRedirectDeflateEncoder

Lasse Højgaard lash at stibosystems.com
Wed Aug 31 08:35:18 EDT 2016


Hi all,

I'm using OpenSAML version 3.2, with an HTTP-Redirect workflow.

Can anyone tell my why the HTTPRedirectDeflateEncoder only supports  DSA-SHA1 and RSA-SHA1 signatures as mentioned here:
https://build.shibboleth.net/nexus/content/sites/site/java-opensaml/3.2.0/apidocs/org/opensaml/saml/saml2/binding/encoding/impl/HTTPRedirectDeflateEncoder.html 
It seems to me, that the signing-algorithm /is indeed/ extracted from the signingCredential.

So: is the documentation wrong, or is there some technical explanation for this limitation?
Follow-up question: is it possible to use RSA-SHA256 for signatures?

Kind regards,
Lasse Højgaard
Consultant

Stibo Systems A/S
  |  8270  |  Højbjerg  |  Denmark
T +45 89 39 13 23  |  M +45 20 42 45 96
lash at stibosystems.com  |  



More information about the dev mailing list