SP metadata that supports both sha1 and sha2?

Cantor, Scott cantor.2 at osu.edu
Wed Jun 25 14:05:56 EDT 2014


> Sorry.  The certificates are in KeyInfo -> X509Data -> X509Certificate.  One
> cert in each ds:Signature block.

Right, but even the path you note there isn't definitive (your second sentence is). A KeyDescriptor also contains a KeyInfo. So it's often difficult to speak informally when it comes to the syntax and have clear communication.

What I presumed was that they were also doing some kind of key rollover here and/or starting to use SHA-2 at runtime, and any or all of that could still be the case. And key rollover would matter a lot of course.

But few vendors do any signing at runtime when they're the SP, so that seems unlikely in hindsight. Unless they do support encryption, which would be a key rollover concern, but they're not likely to do that as part of some kind of SHA-1 retirement plan.

-- Scott



More information about the users mailing list