"Bad signature length" in request

IAM David Bantz dabantz at alaska.edu
Wed Aug 13 18:38:46 UTC 2025


Ah yes, the usual suspect: 4096 cert being used by the SP, not updated from
prior 2048 cert in metadata at the IdP. In this case, oversight on my IdP
side not to incorporate the updated stronger cert for a new instance of the
SP.

David

On Wed, Aug 13, 2025 at 8:52 AM Cantor, Scott <cantor.2 at osu.edu> wrote:

> I would guess, however rusty my crypto, that it's probably getting SHA-256
> as the digest in the signature and it's getting a SHA-512 digested value.
> They're signing with alg A and signaling alg B basically (and of course,
> they shouldn't sign at all, problem solved).
>
> -- Scott
>
>
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250813/318ac901/attachment.htm>


More information about the users mailing list