SP expecting SHA1 or SHA256 algorithm but Shibboleth IDP responding with SHA 512.
Brent Putman
putmanb at georgetown.edu
Wed Jul 13 03:50:16 EDT 2016
On 7/13/16 3:14 AM, Muthuraman Sethuraman Sethuraman (US - Advisory) wrote:
> From the documentation, i found where to configure.
>
> ${idp.home}/conf/idp.properties
> # To default to SHA-1, set to shibboleth.SigningConfiguration.SHA1
> idp.signing.config = shibboleth.SigningConfiguration.SHA1
>
> And restarted the server.
> But even after this configuration change, i still see the saml
> response being signed with sha512 algorithm and its evident from the
> idp-process.log. Is this a configuration issue or a bug?
>
Assuming you did all that correctly, that's further evidence that the
algorithm selection is being driven by the SP's metadata.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160713/bb94f49f/attachment-0001.html>
More information about the users
mailing list