Question about xml-signature algorithm used by Shibboleth IdP

Brent Putman putmanb at georgetown.edu
Wed Aug 17 01:35:01 BST 2011



On 8/16/11 4:14 AM, WULMS Alexander wrote:

>  
> 
> I really appreciate your idea of being able to configure the signing
> algorithm on a relying-party specific basis in v3. It would allow to use
> the strongest signing algorithm supported by an SP.
> 

If you aren't already aware, you might want to take a look at the post
SAML 2.0 extension spec "SAML v2.0 Metadata Profile for Algorithm
Support Version 1.0" [1].  This allows entities to specify in SAML
metadata the crypto algorithms that they support/prefer.  We plan to
support this extension spec in v3 of the IdP.  I think the SP might
already support it to some degree (or maybe I'm just dreaming that, but
Scott will correct me either way).


1. http://wiki.oasis-open.org/security/SAML2MetadataAlgSupport


More information about the users mailing list