Seeking feedback on default encryption algorithm for V4

Ian Young ian at iay.org.uk
Mon Feb 10 11:52:06 EST 2020



> On 2020-02-10, at 15:50, Christopher Bongaarts <cab at umn.edu> wrote:
> 
> I'd have to wonder if the set of SPs with published algorithm support in their metadata overlaps completely with the set of SPs that support AES-GCM...


For UK federation-registered entities:

* 889 have EncryptionMethod

* 691 (78%) include -gcm algorithms (198, 22% not including GCM)

So there are definitely a fair number of SPs declaring a set of EncryptionMethod algorithms not including GCM variants. Of course, some of those declarations will be outdated so that some of those entities will now in fact support GCM.

    -- Ian




-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20200210/d1144a64/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3883 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/dev/attachments/20200210/d1144a64/attachment.p7s>


More information about the dev mailing list