Question about relying-party-system.xml

Cantor, Scott cantor.2 at osu.edu
Wed Jun 30 21:52:42 UTC 2021


On 6/30/21, 3:20 PM, "users on behalf of Ullfig, Roberto Alfredo" <users-bounces at shibboleth.net on behalf of rullfig at uic.edu> wrote:

>As for SHA1 vs SHA256 I was thinking in line of a very old application that doesn't know how to deal with a
> SHA256 signing certificate.

I know that's what you meant, but that pales in comparison to the systems likely to break for the more obvious reason, so that's why I raised it.

There is no absolute answer. Any time you ask "is it possible for an SP to break if I do X?" the answer is "probably". Is it likely? Not super likely, no. Just old Linux servers that have libraries without SHA-2 support mostly.

-- Scott




More information about the users mailing list