[SOLVED] Re: RC4 and ECDHE_RSA

Martin Haase Martin.Haase at DAASI.de
Wed Aug 21 07:51:52 EDT 2013


Hi Ian,

thanks for this! The articles you cited were also among the ones i had
found.
I tried the reordering, nothing happened. Then I realized that the
sunjce_provider.jar was still being used by the IdP. I fixed this by
copying bcprov-jdk15-1.46.jar to $JAVA_HOME/lib/ext/: seemingly the jar
that lives in idp.war was not picked up. And it worked!!!

> Switching to http:// would obviously do it (and there's really no reason to use TLS for metadata unless the metadata is itself unsigned).  The other alternative would be to get them to use a more compatible set of cipher suites on their side.
>
> Do you have any idea what their implementation is based on?  When things like this come up I always worry that they are advance warnings of some platform distribution's default policies, which might affect lots of people in the long run.  It's more often just a random person's individual choice, though.
That's a good point... I'd need to discuss this with the guy responsible.

Thanks again for your quick answer,
Martin

-- 
Dr. Martin Haase, Solutions Engineer

DAASI International GmbH        
Europaplatz 3                   
D-72072 Tübingen                
Germany                    

phone: +49 7071 407109-6
fax:   +49 7071 407109-9  
email: martin.haase at daasi.de
web:   www.daasi.de

Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2345 bytes
Desc: S/MIME Kryptografische Unterschrift
Url : http://shibboleth.net/pipermail/users/attachments/20130821/925749cc/attachment.bin 


More information about the users mailing list