Question around SP security-policy.xml and DefaultBlacklist

Peter Schober peter.schober at univie.ac.at
Wed Sep 13 01:55:04 EDT 2017


* Reid Watson <reid.watson at auckland.ac.nz> [2017-09-13 06:56]:
> Disabling this option globally affects all sites via
> “<AlgorithmBlacklist includeDefaultBlacklist="false"/>”.
> Im wondering if I can isolate to one site, in particular the vendor
> IDP by creating two security-policy.xml and assigning per site

While the SP does have a RelyingParty configuration (with stuff
specific for an IDP) that only overrides things from the Application,
AFAIU, and SecurityPolicy(Provider) is not part of the Application
content.
https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty
I also see nothing in the documented attributes that deals with
blacklisted crypto algorithms, so it seems to me it's not possible to
set this per IDP.
-peter


More information about the users mailing list