Changing signing algorithm for a specific relying party

Wessel, Keith kwessel at illinois.edu
Tue Jan 5 14:52:06 EST 2016


We have a vendor, Qualys, whose connection with our IDP has broken since our upgrade to V3. They're getting an error trying to validate the signature on the assertion we're sending to them. I suspect they're not able to handle SSHA-256 signatures.

I don't see any info in the relying party docs for V3 on how to override the signing algorithm for a specific SP. What would I need to add to the block in my relying-party.xml for Qualys to use SSHA-1 signatures? I already have a block for Qualys to not encrypt assertions, but I'm not sure how to set the signing algorithm.

Thanks,
Keith



More information about the users mailing list