Seeking feedback on default encryption algorithm for V4
Christopher Bongaarts
cab at umn.edu
Fri Feb 21 11:25:35 EST 2020
On 2/21/2020 10:04 AM, Cantor, Scott wrote:
> I was referring to having to accommodate SPs that don't handle SHA-2. I myself have none left.
As a data point, out of several hundred SPs we deal with, we have two
cases where SHA-1 is still. One is an ancient Shib SP on an ancient
OS. The other is Weblogic built-in SAML support, and I'm not entirely
sure it's still necessary (they also needed a few other tweaks like
signing assertions instead of responses, and we didn't exhaustively test
all combinations).
Both are easily accommodated with relying-party exceptions.
--
%% Christopher A. Bongaarts %% cab at umn.edu %%
%% OIT - Identity Management %% http://umn.edu/~cab %%
%% University of Minnesota %% +1 (612) 625-1809 %%
More information about the dev
mailing list