Question about xml-signature algorithm used by Shibboleth IdP
Brent Putman
putmanb at georgetown.edu
Wed Aug 17 01:35:01 BST 2011
On 8/16/11 4:14 AM, WULMS Alexander wrote:
>
>
> I really appreciate your idea of being able to configure the signing
> algorithm on a relying-party specific basis in v3. It would allow to use
> the strongest signing algorithm supported by an SP.
>
If you aren't already aware, you might want to take a look at the post
SAML 2.0 extension spec "SAML v2.0 Metadata Profile for Algorithm
Support Version 1.0" [1]. This allows entities to specify in SAML
metadata the crypto algorithms that they support/prefer. We plan to
support this extension spec in v3 of the IdP. I think the SP might
already support it to some degree (or maybe I'm just dreaming that, but
Scott will correct me either way).
1. http://wiki.oasis-open.org/security/SAML2MetadataAlgSupport
More information about the users
mailing list