Trouble Configuring SHA-256 Signatures
Marvin Addison
marvin.addison at gmail.com
Sat Jan 17 11:51:49 EST 2015
SOLVED.
The problem had nothing to do with which OpenSAML configuration bean we
used or the configured algorithms. It turns out that a CAS client component
was overwriting the OpenSAML security settings via a call
to DefaultBootstrap.bootstrap(). I filed an issue with the Java CAS client
project if anyone is interested in the details:
https://issues.jasig.org/browse/CASC-237
Anyone that's using the Java CAS client libraries
(e.g. shib-cas-authenticator folks) on the IdP and setting custom OpenSAML
security settings may want to confirm whether they are affected by this
issue. I'm fairly certain that one would have to be using the
Saml11AuthenticationFilter component to be affected, so it's doubtful
shib-cas-authenticator deployers would be affected. For those folks like us
doing Shib-CAS integration via REMOTE_USER, I would think it's more likely.
M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150117/5eab5ef7/attachment.html
More information about the users
mailing list