Experience with SPs requiring 'large' symmetric encryption keys
Cantor, Scott
cantor.2 at osu.edu
Tue Apr 9 10:59:48 EDT 2013
On 4/9/13 10:12 AM, "Tom Poage" <tfpoage at ucdavis.edu> wrote:
>Part of the motivation behind my question is I'd thrown together a
>RedHat/CentOS/... RPM to install the Java 7 JCE 'unlimited strength'
>policy JARs and persist them across Java (java-1.7.0-oracle) updates. I
>don't recall seeing (SAML specs) whether an SP can request--or, more
>importantly, require--a minimum (encryption) security strength in
>returned assertions, so maybe the point of making the RPM more widely
>available is moot. Works with it, works without. :-)
It can, but you will not see that in practice, no.
But I think having something like that available would be really good.
-- Scott
More information about the users
mailing list