Question about xml-signature algorithm used by Shibboleth IdP

Chad La Joie lajoie at itumi.biz
Fri Aug 12 16:50:39 BST 2011


In theory they are configurable, but no there is no documentation on
doing it.  It's a pretty low level setting and we're restricted in
some ways by the underlying XML security library itself.  We're
working on fixing a lot of the pain points for v3 and then we'll
expose config options.

On Fri, Aug 12, 2011 at 11:46, WULMS Alexander
<Alexander.WULMS at swift.com> wrote:
> Hi,
>
>
>
> I have noticed that by default, Shibboleth 2.3 uses SHA1 algorithm to
> calculate the hash-value for the xml-signature (to build the SAML response)
> and then encrypts the hash with RSA-2048.
>
>
>
> Are the algorithms used to calculate the signature configurable? I have not
> been able to find information about this in the documentation. I assume that
> the encryption algorithm is determined by the certificate used but I don’t
> know about the hash algorithm.
>
>
>
> Thanks and brs,
>
> Alex
>
>
>
>
>
> Alex Wulms
> Lead Developer, Swift.com development
> Tel: + 32 2 655 3931
>
> S.W.I.F.T. SCRL
>
> This e-mail and any attachments thereto may contain information which is
> confidential and/or proprietary and intended for the sole use of the
> recipient(s) named above. If you have received this e-mail in error, please
> immediately notify the sender and delete the mail.  Thank you for your
> co-operation.  SWIFT reserves the right to retain e-mail messages on its
> systems and, under circumstances permitted by applicable law, to monitor and
> intercept e-mail messages to and from its systems.
>
>
> Please visit http://www.swift.com for more information about SWIFT.
>
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list