Seeking feedback on default encryption algorithm for V4

Cantor, Scott cantor.2 at osu.edu
Mon Feb 10 08:31:11 EST 2020


> Well, I'm assuming deployers can both change that property as desired (which
> would be mentioned in the release notes, I'm guessing) as well as override that
> per relying party, for SPs lacking the metadata extension?

It's similar to the SHA1/SHA2 issue. Things get messy when you start combining both of them because the bean that has to be configured is a single object that contains signing and encryption settings, so it takes 4 of them to cover all of these cases, but I don't think SHA1 is much of a need anymore either.

-- Scott



More information about the dev mailing list