signing algorithm per SP?

Ryan Suarez ryan.suarez at sheridancollege.ca
Tue Oct 11 12:14:34 EDT 2016


Greetings,

We’ve cutover our IdP from v2 to v3.2.1.  One of our internal SP’s have an outdated openssl library:

2016-10-11 11:05:07 DEBUG XMLTooling.TrustEngine.PKIX [4]: Caught an XMLSecurity exception verifying signature: OpenSSL:Hash - SHA256 not supported by this version of OpenSSL


Unfortunately the SP is running end-of-life RHEL4 so there is no updates to openssl.  The folks that manage this system say they are unable to migrate to a newer redhat in the short term.  Is there a way in IdP to sign using SHA1 just for this SP?


Regards,

Ryan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20161011/5743d3f0/attachment.html>


More information about the users mailing list