Question around SP security-policy.xml and DefaultBlacklist

Cantor, Scott cantor.2 at osu.edu
Wed Sep 13 09:31:51 EDT 2017


On 9/13/17, 12:55 AM, "users on behalf of Reid Watson" <users-bounces at shibboleth.net on behalf of reid.watson at auckland.ac.nz> wrote:

> Im wondering if I can isolate to one site, in particular the vendor IDP by creating two security-policy.xml and assigning per site 

No, algorithms are at too low a level for that. Just tell them not to encrypt. That's more honest to themselves and their users anyway. Or turn it on if you want I guess, it's not as though you're the one screwing it up.

-- Scott




More information about the users mailing list