[EXT] Re: encrypt assertion with static AES key

Cantor, Scott cantor.2 at osu.edu
Fri Apr 11 14:06:11 UTC 2025


> We will probably just disable encryption for this provider. 

Tha is typically what I do but I do like to poke and fond out what implementation I'm dealing with. Bugs become much simpler to exploit with encryption off.

-- Scott




More information about the users mailing list