Seeking feedback on default encryption algorithm for V4

Michael A Grady mgrady at unicon.net
Fri Feb 21 11:46:00 EST 2020


> On Feb 21, 2020, at 10:25 AM, Christopher Bongaarts <cab at umn.edu> wrote:
> 
> On 2/21/2020 10:04 AM, Cantor, Scott wrote:
>> I was referring to having to accommodate SPs that don't handle SHA-2. I myself have none left.
> 
> As a data point, out of several hundred SPs we deal with, we have two cases where SHA-1 is still.  One is an ancient Shib SP on an ancient OS.  The other is Weblogic built-in SAML support, and I'm not entirely sure it's still necessary (they also needed a few other tweaks like signing assertions instead of responses, and we didn't exhaustively test all combinations).
> 
> Both are easily accommodated with relying-party exceptions.
> 

O365 metadata still indicates that SHA-1 signing is required. Don't even need an override for that, though, since they use the defined extension to indicate that.

--
Michael A. Grady
IAM Architect, Unicon, Inc.



-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20200221/8e9de39e/attachment.html>


More information about the dev mailing list