SHA 256
csross
cross at hccs.com
Thu Nov 5 16:06:06 EST 2015
I see the keygen.sh file on a server with shibboleth-sp-2.5.3 installed still
has default_md=sha1. Is this what results in a certificate with Signature
Algorithm: sha1WithRSAEncryption please?.
Is this setting what is being referred to in the ADFS documentation
"Shibboleth uses the Secure Hash Algorithm 1 (SHA-1) for signing
operations"?
If it is,
1) If I want to generate a certificate with Signature Algorithm:
sha256WithRSAEncryption, can I modify the default_md= setting in keygen.sh
to produce that entry? Is there a document with the available entries for
default_md=? I know I can generate my own key/cert pair but if the tool
works then I want to use it.
2) If I make this change can the ADFS users set to SHA256?
3) Will this work on version 2.4.3 (I know it is old) as long as my openssl
version supports sha2?
Thank you for your help.
--
View this message in context: http://shibboleth.1660669.n2.nabble.com/SHA-256-tp7615722p7620423.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.
More information about the users
mailing list