SP metadata that supports both sha1 and sha2?

Cantor, Scott cantor.2 at osu.edu
Wed Jun 25 13:49:32 EDT 2014


> We have two pieces of SP metadata for Gartner - both using the same
> entityID, and the same endpoint URLs.
> One metadata file is signed using sha1, and includes certificate A.
> The other metadata file is signed using sha256, and includes certificate B.

When you say "includes certificate X", we don't know what that means for certain. Saying metadata includes a certificate generally means it includes a KeyDescriptor for that certificate and that matters a lot. A certificate inside a Signature as a KeyInfo hint means essentially nothing.

> Is it possible / correct / valid to combine both pieces of metadata into a single
> EntityDescriptor entry that contains both that sha1 and sha256 signatures
> (and the certs used to generate them)?

No.

-- Scott



More information about the users mailing list