Vulnerability fixes

Cantor, Scott cantor.2 at osu.edu
Tue Dec 23 15:58:57 EST 2014


On 12/23/14, 8:52 PM, "Sathish Anickode" 
<SAnickode at skytouchtechnology.com> wrote:

>One of the alternate W3C recommendation is to include a HMAC of the 
>encrypted message if AES-GCM is not available. I am not sure if SP will 
>be able to handle such modifications.  Does Shibboleth support this 
>mechanism?

No, because XML Encryption does not support that. I don't know what 
recommendation you're looking at, but it didn't come from the W3C working 
group I was in (or if it did, please point it out, so I can go complain to 
somebody).

I fought for the addition of a CBC+HMAC combination in addition to GCM so 
that there would be a standard way to do this that had any prayer of 
adoption, and some of the vendors shot me down. That was about my last 
straw working on standards. It was deliberate sabotage of the technology 
by certain vendors who knew that their implementations were the only ones 
capable of supporting non-broken algorithms for the foreseeable future.

-- Scott



More information about the users mailing list