Can shibboleth send dsa-sha1 signatures?
Matheesha Weerasinghe
matheesha at gmail.com
Fri Jul 25 19:59:25 EDT 2014
Just to wrap up Shibboleth can send dsa-sha1 after I created certs as
appropriate. I've just tested it.
Cheers
Mat
On 25 July 2014 21:21, Matheesha Weerasinghe <matheesha at gmail.com> wrote:
> Thanks Scott.
>
>
> On 25 July 2014 17:29, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
>> On 7/25/14, 8:14 AM, "Matheesha Weerasinghe" <matheesha at gmail.com> wrote:
>> >
>> >I've tested as per
>> >
>> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty
>> ><
>> https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty
>> >> by adding a
>> >signingAlg ="http://www.w3.org/2000/09/xmldsig#dsa-sha1" in the
>> ><relyingparty> and <ApplicationOverride> elements. This however now
>> >doesn't send a signed request at all.
>> > I just have signing="true" in both of them.
>>
>> There'd probably be something in the log about it, but I think if it gets
>> an error using a configured algorithm when it's sending requests that it
>> probably will just fall back to unsigned.
>>
>> Note that you certainly can't do this without creating a different key for
>> the SP. You can't use an RSA key and sign with DSA.
>>
>> All that said, I have no earthly idea if DSA will work. I doubt it.
>>
>> -- Scott
>>
>> --
>> To unsubscribe from this list send an email to
>> users-unsubscribe at shibboleth.net
>>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140726/33ec66e4/attachment.html
More information about the users
mailing list