sp(2.5.5) <-> idp(3.1.2) and ecdsa certs

Cantor, Scott cantor.2 at osu.edu
Tue Oct 20 09:34:01 EDT 2015


On 10/20/15, 7:42 AM, "users on behalf of Jarno Huuskonen" <users-bounces at shibboleth.net on behalf of jarno.huuskonen at uef.fi> wrote:

>(I had to disable encryption for that SP in (idp: relying-party.xml),
>this is probably because xmlenc keytransport algorithms
>use rsa?:

Yes, I don't support ECDH encryption.

>I tested that SP can verify ecdsa signed metadata, so ecdsa signed
>response probably works.

Apparently not. What was the metadata signed with?

-- Scott



More information about the users mailing list