algorithm URI was invalid: http://www.w3.org/2001/04/xmlenc#aes128-cbc
Brent Putman
putmanb at georgetown.edu
Thu Sep 26 15:18:29 EDT 2013
On 9/26/13 2:03 PM, Cantor, Scott wrote:
>
> Were that the case, though, there's no way it would work for *any* SPs. I
> can't think of any scenario in today's IdP that could be specific to one
> SP unless some kind of interaction were possible between code that is
> looking for the RSA key in metadata.
Right, I don't see any scenario either for per-SP behavior either. I'm
literally just trying to understand at a code level exactly what is
happening. Without that, everything else is speculation.
> So perhaps the error is somehow
> mis-reporting itself as being about the AES algorithm.
Maybe, that's why I was interested in the additional logging.
>
> A lot of this comes down to that issue. All the messages have alluded to
> the claim that encryption is working for some. I think that claim has to
> be examined.
I was pretty much half-way assuming that that could not be the case.
Based on the code, I don't see any way that this can be SP-specific.
It's too low-level. It's not even related to metadata. I'm (almost)
100% certain It's either Santuario or something at the JCA crypto
provider level, and none of that has anything to do with SAML or Shib.
More information about the users
mailing list