SHA1 signed authn request issue

Cantor, Scott cantor.2 at osu.edu
Fri Mar 10 15:39:31 EST 2017


> We have a third party vendor which is sending a signed authentication
> request but with SHA1. IdP v3.3 is rejecting the request with

The failure isn't a SHA1 issue, we don't blacklist it. You just have the wrong metadata or they have the wrong key. Nothing mysterious, and the error in the log is telling you this outright (signature verification failed). Don't go looking for reasons, that is the reason.

-- Scott



More information about the users mailing list