SHA 256

csross cross at hccs.com
Thu Nov 5 16:33:05 EST 2015


Thank you for the answers.

I asked this because it is in the keygen.sh file, which was in the
shibboleth SP install.  How could www.openssl.org know about that?  Is
keygen.sh something you got from openssl.org?   If not, is their a doc that
shows the supported entries please and what are their results. 
-----------------------------
If I want to generate a certificate with Signature Algorithm: 
>sha256WithRSAEncryption, can I modify the default_md= setting in keygen.sh 
>to produce that entry? 

I don't know. See www.openssl.org (and if you can't find anything, then
you've found whatever I would have found). 
-----------------------------
With regards to this question.  Thank you.  There was a shib doc that
indicated that older openssl didn't support sha2 which is why ADFS had to
specify SHA1?  Is that correct and what affects this?

>Is this setting what is being referred to in the ADFS documentation 
>"Shibboleth uses the Secure Hash Algorithm 1 (SHA-1) for signing 
>operations"? 

No, not at all. 

The SP doesn't sign anything by default that ADFS cares about except logout
requests. That documentation is talking about the IdP. 

Thanks



--
View this message in context: http://shibboleth.1660669.n2.nabble.com/SHA-256-tp7615722p7620426.html
Sent from the Shibboleth - Users mailing list archive at Nabble.com.


More information about the users mailing list