Experience with SPs requiring 'large' symmetric encryption keys

Cantor, Scott cantor.2 at osu.edu
Tue Apr 9 10:59:48 EDT 2013


On 4/9/13 10:12 AM, "Tom Poage" <tfpoage at ucdavis.edu> wrote:

>Part of the motivation behind my question is I'd thrown together a
>RedHat/CentOS/... RPM to install the Java 7 JCE 'unlimited strength'
>policy JARs and persist them across Java (java-1.7.0-oracle) updates. I
>don't recall seeing (SAML specs) whether an SP can request--or, more
>importantly, require--a minimum (encryption) security strength in
>returned assertions, so maybe the point of making the RPM more widely
>available is moot. Works with it, works without. :-)

It can, but you will not see that in practice, no.

But I think having something like that available would be really good.

-- Scott




More information about the users mailing list