Question around SP security-policy.xml and DefaultBlacklist

Reid Watson reid.watson at auckland.ac.nz
Wed Sep 13 00:55:23 EDT 2017


Hi Everyone, 

- Sorry if this question has been posted before but I would just like to double check 

We currently run SP 2.5.2 supporting over 800 sites, we have one vendor that requires the legacy algorithm PKCS 1.5 to be enabled, 

Log 
2017-09-06 21:07:24 WARN XMLTooling.Decrypter [1]: XMLSecurity exception while decrypting key: XSECAlgorithmMapper::mapURIToHandler - URI http://www.w3.org/2001/04/xmlenc#rsa-1_5 disallowed by whitelist/blacklist policy
    
- Disabling this option globally affects all sites via “<AlgorithmBlacklist includeDefaultBlacklist="false"/>”.
- Im wondering if I can isolate to one site, in particular the vendor IDP by creating two security-policy.xml and assigning per site 

The vendor advised this will be fixed next year but has anyone encountered this issue before and created a workaround ?

Cheers

Reid 
 


More information about the users mailing list