<html><head><meta http-equiv="Content-Type" content="text/html; charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On Feb 21, 2020, at 10:25 AM, Christopher Bongaarts <<a href="mailto:cab@umn.edu" class="">cab@umn.edu</a>> wrote:</div><br class="Apple-interchange-newline"><div class="">On 2/21/2020 10:04 AM, Cantor, Scott wrote:<br class=""><blockquote type="cite" class="">I was referring to having to accommodate SPs that don't handle SHA-2. I myself have none left.<br class=""></blockquote><br class="">As a data point, out of several hundred SPs we deal with, we have two cases where SHA-1 is still.  One is an ancient Shib SP on an ancient OS.  The other is Weblogic built-in SAML support, and I'm not entirely sure it's still necessary (they also needed a few other tweaks like signing assertions instead of responses, and we didn't exhaustively test all combinations).<br class=""><br class="">Both are easily accommodated with relying-party exceptions.<br class=""><br class=""></div></blockquote><br class=""></div><div>O365 metadata still indicates that SHA-1 signing is required. Don't even need an override for that, though, since they use the defined extension to indicate that.</div><br class=""><div class="">
<div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;">--<br class="">Michael A. Grady<br class="">IAM Architect, Unicon, Inc.</div><div style="color: rgb(0, 0, 0); font-family: Helvetica; font-size: 14px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" class=""><br class=""></div><br class="Apple-interchange-newline">

</div>
<br class=""></body></html>