Seeking feedback on default encryption algorithm for V4

Alex Stuart Alex.Stuart at jisc.ac.uk
Mon Feb 17 09:18:54 EST 2020


Hello Scott,

> On 7 Feb 2020, at 16:08, Cantor, Scott <cantor.2 at osu.edu> wrote:
> 
> We're finalizing the V4 defaults, and apart from a few obvious ones, the biggest remaining question is whether to flip the default encryption algorithms from AES-CBC over to AES-GCM for new installs. Upgrades would need to inherit the existing default, so we're not going to actually change the default internally, but the shipping configuration can be set differently, much as with the local storage change.
> 
> I think it's now or never to do this, because there is no time at which there will be a majority of non-Shibboleth SPs that support GCM, so the situation is not going to be materially different later. It just is what it is: CBC is and has been broken for a decade and the only safe algorithm available is GCM. Virtually all but the most outdated Shibboleth SPs support it. I have no idea what else does and just take the default position that most nothing does. I'm sure a few do, but it's an easier planning assumption.
> 
> So there's no illusion that it won't require effort by deployers to use it, and if people want to just not care and toggle the property off, they're free to do that.
> 
> I just think we're obligated to ship secure configurations as best we can, and that is the only secure configuration we have.
> 
> Admittedly, I'm also less impacted by the fallout because apart from member support, I really just don't have to care too much what trouble this causes. So I'm inclined to go along with the majority on it.
> 

The UK federation support & dev teams concur with your reasoning for changing the default from CBC to GCM in the V4 release.

For a newly-deployed IdP to work successfully in the UK federation, the deployer will have to make at least 3 configuration changes (for our metadata source, to enable eduPersonTargetedID and to allow the SAML 1 backchannel) which they will find documented on our website. Our advice re: XML encryption defaults (whether it's to make a further 1-line change to idp.properties to back-off to CBC, or whether we'll produce some guidance about how to test and enable CBC selectively following https://wiki.shibboleth.net/confluence/display/IDP4/AlgorithmFilter) will also go there. Yes, we'll have to do some work to support this change; I think we're OK with that.

Alex

—
Alex Stuart, Technical Development Manager (Trust and Identity)
alex.stuart at jisc.ac.uk









-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4313 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/dev/attachments/20200217/386734f8/attachment.p7s>


More information about the dev mailing list