<div dir="ltr"><div>Just to wrap up Shibboleth can send dsa-sha1 after I created certs as appropriate. I&#39;ve just tested it.</div><div><br></div><div>Cheers</div><div><br></div><div>Mat </div></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On 25 July 2014 21:21, Matheesha Weerasinghe <span dir="ltr">&lt;<a href="mailto:matheesha@gmail.com" target="_blank">matheesha@gmail.com</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div dir="ltr">Thanks Scott.</div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><br><div class="gmail_quote">On 25 July 2014 17:29, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br>

<blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;padding-left:1ex;border-left-color:rgb(204,204,204);border-left-width:1px;border-left-style:solid"><div>On 7/25/14, 8:14 AM, &quot;Matheesha Weerasinghe&quot; &lt;<a href="mailto:matheesha@gmail.com" target="_blank">matheesha@gmail.com</a>&gt; wrote:<br>


&gt;<br>
&gt;I&#39;ve tested as per<br>
&gt;<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty</a><br>
&gt;&lt;<a href="https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty" target="_blank">https://wiki.shibboleth.net/confluence/display/SHIB2/NativeSPRelyingParty</a><br>
&gt;&gt; by adding a<br>
&gt;signingAlg =&quot;<a href="http://www.w3.org/2000/09/xmldsig#dsa-sha1" target="_blank">http://www.w3.org/2000/09/xmldsig#dsa-sha1</a>&quot; in the<br>
&gt;&lt;relyingparty&gt; and &lt;ApplicationOverride&gt; elements. This however now<br>
&gt;doesn&#39;t send a signed request at all.<br>
&gt; I just have signing=&quot;true&quot; in both of them.<br>
<br>
</div>There&#39;d probably be something in the log about it, but I think if it gets<br>
an error using a configured algorithm when it&#39;s sending requests that it<br>
probably will just fall back to unsigned.<br>
<br>
Note that you certainly can&#39;t do this without creating a different key for<br>
the SP. You can&#39;t use an RSA key and sign with DSA.<br>
<br>
All that said, I have no earthly idea if DSA will work. I doubt it.<br>
<span><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div>
</div></div></blockquote></div><br></div>