Seeking feedback on default encryption algorithm for V4

Christopher Bongaarts cab at umn.edu
Fri Feb 21 11:25:35 EST 2020


On 2/21/2020 10:04 AM, Cantor, Scott wrote:
> I was referring to having to accommodate SPs that don't handle SHA-2. I myself have none left.

As a data point, out of several hundred SPs we deal with, we have two 
cases where SHA-1 is still.  One is an ancient Shib SP on an ancient 
OS.  The other is Weblogic built-in SAML support, and I'm not entirely 
sure it's still necessary (they also needed a few other tweaks like 
signing assertions instead of responses, and we didn't exhaustively test 
all combinations).

Both are easily accommodated with relying-party exceptions.

-- 
%%  Christopher A. Bongaarts   %%  cab at umn.edu          %%
%%  OIT - Identity Management  %%  http://umn.edu/~cab  %%
%%  University of Minnesota    %%  +1 (612) 625-1809    %%



More information about the dev mailing list