[SOLVED] Re: RC4 and ECDHE_RSA
Martin Haase
Martin.Haase at DAASI.de
Wed Aug 21 07:51:52 EDT 2013
Hi Ian,
thanks for this! The articles you cited were also among the ones i had
found.
I tried the reordering, nothing happened. Then I realized that the
sunjce_provider.jar was still being used by the IdP. I fixed this by
copying bcprov-jdk15-1.46.jar to $JAVA_HOME/lib/ext/: seemingly the jar
that lives in idp.war was not picked up. And it worked!!!
> Switching to http:// would obviously do it (and there's really no reason to use TLS for metadata unless the metadata is itself unsigned). The other alternative would be to get them to use a more compatible set of cipher suites on their side.
>
> Do you have any idea what their implementation is based on? When things like this come up I always worry that they are advance warnings of some platform distribution's default policies, which might affect lots of people in the long run. It's more often just a random person's individual choice, though.
That's a good point... I'd need to discuss this with the guy responsible.
Thanks again for your quick answer,
Martin
--
Dr. Martin Haase, Solutions Engineer
DAASI International GmbH
Europaplatz 3
D-72072 Tübingen
Germany
phone: +49 7071 407109-6
fax: +49 7071 407109-9
email: martin.haase at daasi.de
web: www.daasi.de
Sitz der Gesellschaft: Tübingen
Registergericht: Amtsgericht Stuttgart, HRB 382175
Geschäftsleitung: Peter Gietz
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 2345 bytes
Desc: S/MIME Kryptografische Unterschrift
Url : http://shibboleth.net/pipermail/users/attachments/20130821/925749cc/attachment.bin
More information about the users
mailing list