Seeking feedback on default encryption algorithm for V4
Michael A Grady
mgrady at unicon.net
Fri Feb 21 11:46:00 EST 2020
> On Feb 21, 2020, at 10:25 AM, Christopher Bongaarts <cab at umn.edu> wrote:
>
> On 2/21/2020 10:04 AM, Cantor, Scott wrote:
>> I was referring to having to accommodate SPs that don't handle SHA-2. I myself have none left.
>
> As a data point, out of several hundred SPs we deal with, we have two cases where SHA-1 is still. One is an ancient Shib SP on an ancient OS. The other is Weblogic built-in SAML support, and I'm not entirely sure it's still necessary (they also needed a few other tweaks like signing assertions instead of responses, and we didn't exhaustively test all combinations).
>
> Both are easily accommodated with relying-party exceptions.
>
O365 metadata still indicates that SHA-1 signing is required. Don't even need an override for that, though, since they use the defined extension to indicate that.
--
Michael A. Grady
IAM Architect, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20200221/8e9de39e/attachment.html>
More information about the dev
mailing list