RelyingPartyOverrides

Ian Young ian at iay.org.uk
Tue Mar 24 13:40:09 EDT 2015


> On 24 Mar 2015, at 17:06, Michael O Holstein <michael.holstein at csuohio.edu> wrote:
> 
> since the default certs are SHA256 and you can't sign SHA1 with that

Actually, you can. The digest method used within a certificate does not restrict the ways in which the key associated with the certificate can be used to sign SAML messages.

    -- Ian




-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5250 bytes
Desc: not available
Url : http://shibboleth.net/pipermail/users/attachments/20150324/050a57e8/attachment.bin 


More information about the users mailing list