Shibboleth Service Provider with RSA-PSS

Dennis Nikolay d.nikolay at wikom.de
Mon May 16 09:48:04 UTC 2022


This is very unfortunate, as RSA-PSS is one of the signature algorithms the BSI approved for governmental software in Germany. Furthermore the MUK identity provider, which is to become the central login for business related eGovernment services in Germany as per OZG, decided to require this signature algorithm.
This does not seem to be a fringe use case so I am surprised that there are no plans for Shibboleth to support RSA-PSS.


> Am 12.05.2022 um 14:20 schrieb Cantor, Scott via users <users at shibboleth.net>:
> 
> On 5/12/22, 5:04 AM, "users on behalf of Dennis Nikolay" <users-bounces at shibboleth.net on behalf of d.nikolay at wikom.de> wrote:
> 
>> It does not seem like Shibboleth Service Provider supports this or am I missing something?
> 
> No, but I will be fascinated to learn what does. Unlike RSA-OAEP, AES-CBC is actually  broken and yet we are virtually the only implementation supporting AES-GCM.
> 
> -- Scott
> 
> 
> -- 
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list