<div dir="ltr">We&#39;re trying to work through an issue with a vendor re: the InCommon mandated move from sha1 to sha256 hashing.<div><br></div><div>Their concern is that the signature algorithm used when signing our public key is sha1, and have asked that we retest using a cert that&#39;s using sha256.</div>

<div><br></div><div>The instructions in the shib wiki don&#39;t mention having to reissue certs, and we have other vendors who were able to use the sha256 configuration.</div><div><br></div><div>Is this vendor request needed / reasonable?  Is it a red herring?</div>

<div><br></div><div>Liam</div></div>