<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <br>
    <br>
    <div class="moz-cite-prefix">On 10/19/15 12:25 PM, Cantor, Scott
      wrote:<br>
    </div>
    <blockquote cite="mid:822CC1E7-8628-4340-A610-548E62A5244C@osu.edu"
      type="cite"><br>
      <pre wrap="">
Yes, but since he managed to generate a signature with that algorithm, I'm sure it's fine. </pre>
    </blockquote>
    <br>
    I was thinking of some very low-level bug in the actual signature
    crypto impl such that Java can't validate it.  Such that one of them
    is broken (not making any claims as to which).<br>
    <br>
    <br>
    <blockquote cite="mid:822CC1E7-8628-4340-A610-548E62A5244C@osu.edu"
      type="cite">
      <pre wrap="">Most anything recent now actually does have EC.</pre>
    </blockquote>
    <br>
    All of my current test environments are RHEL 5.x, which doesn't
    support (b/c OpenSSL 0.9.8).  Think I can get a RHEL 6.x. or 7.x.<br>
    <br>
    <br>
    <blockquote cite="mid:822CC1E7-8628-4340-A610-548E62A5244C@osu.edu"
      type="cite">
      <pre wrap="">
I've only tested the low-level crypto against the interop test vectors, nothing in SAML space.

</pre>
    </blockquote>
    <br>
    Ok.  But technically there's no "SAML" here, since it's the Redirect
    binding signature, not XML signature. I mean, it's just a raw
    signature, aside from the details of binding encoding.<br>
    <br>
    <br>
    <blockquote cite="mid:822CC1E7-8628-4340-A610-548E62A5244C@osu.edu"
      type="cite">
      <pre wrap="">I personally wouldn't be wasting much time on it at the SP end, I'd see if the IdP can generate the signatures and if the SP can read them before spending much time on anything else.</pre>
    </blockquote>
    <br>
    That would be a useful test, but might be difficult/impossible to
    get the IdP to issue a Redirect binding back to the SP on SSO.<br>
    <br>
    I was going to at least see if I could just reproduce the problem,
    using an SP + new enough OpenSSL for EC support.<br>
  </body>
</html>