Vulnerability fixes
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 23 15:58:57 EST 2014
On 12/23/14, 8:52 PM, "Sathish Anickode"
<SAnickode at skytouchtechnology.com> wrote:
>One of the alternate W3C recommendation is to include a HMAC of the
>encrypted message if AES-GCM is not available. I am not sure if SP will
>be able to handle such modifications. Does Shibboleth support this
>mechanism?
No, because XML Encryption does not support that. I don't know what
recommendation you're looking at, but it didn't come from the W3C working
group I was in (or if it did, please point it out, so I can go complain to
somebody).
I fought for the addition of a CBC+HMAC combination in addition to GCM so
that there would be a standard way to do this that had any prayer of
adoption, and some of the vendors shot me down. That was about my last
straw working on standards. It was deliberate sabotage of the technology
by certain vendors who knew that their implementations were the only ones
capable of supporting non-broken algorithms for the foreseeable future.
-- Scott
More information about the users
mailing list