SP metadata that supports both sha1 and sha2?
Cantor, Scott
cantor.2 at osu.edu
Wed Jun 25 13:49:32 EDT 2014
> We have two pieces of SP metadata for Gartner - both using the same
> entityID, and the same endpoint URLs.
> One metadata file is signed using sha1, and includes certificate A.
> The other metadata file is signed using sha256, and includes certificate B.
When you say "includes certificate X", we don't know what that means for certain. Saying metadata includes a certificate generally means it includes a KeyDescriptor for that certificate and that matters a lot. A certificate inside a Signature as a KeyInfo hint means essentially nothing.
> Is it possible / correct / valid to combine both pieces of metadata into a single
> EntityDescriptor entry that contains both that sha1 and sha256 signatures
> (and the certs used to generate them)?
No.
-- Scott
More information about the users
mailing list