idp properties - sha1

Peter Schober peter.schober at univie.ac.at
Sat May 31 21:30:58 UTC 2025


coupons at sccoast.net <coupons at sccoast.net> [2025-05-30 21:23 CEST]:
> Setting up a new Shib 5.x IdP, we have ancient metadata with
> signing/encryption certs created in SHA-1 format.

If you mean the signature algorithm for any (likely self-signed)
certificates embeeded in metadata: Is there an actual problem you're
trying to fix? Then what's the error message from the log files?

With most deployments the signature on a certificate is irrelevant
(the X.509 certificate is merely used as a container for a public
key), so the algorithm used for that signature (SHA-1 or otherwise) is
also irrelevant.

> To make the new Shib 5.x work with metadata containing SHA-1 certs
> would the only change be in the idp.properties file with these two
> parameters?

You make it sound like the IDP is refusing to work with these
certificates -- is that actually the case? What's the error message
from the log file?

-peter


More information about the users mailing list