<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<p><br>
</p>
<br>
<div class="moz-cite-prefix">On 7/6/16 5:40 PM, Cantor, Scott wrote:<br>
</div>
<blockquote
cite="mid:9846A6064BD102419D06814DD0D78DE11298BFD2@CIO-TNC-D2MBX02.osuad.osu.edu"
type="cite"><br>
<pre wrap="">I don't think we're using GCM by default for XML Encryption though, are we? </pre>
</blockquote>
<br>
Not by default, but it would if the metadata said to via the
algorithm extensions (which I think the Shib SP metadata does by
default IIRC) and it was supported by the platform (security
providers).<br>
<br>
<blockquote
cite="mid:9846A6064BD102419D06814DD0D78DE11298BFD2@CIO-TNC-D2MBX02.osuad.osu.edu"
type="cite">
<pre wrap="">In fact, GCM didn't even work properly with Java 7's JCE, that I recall.</pre>
</blockquote>
<br>
I'm not sure, I can't keep them straight. It might not with Oracle's
default security provider set (although I could be wrong), but
pretty sure it does with BC configured.<br>
<br>
<br>
If there's any question, earlier on in the logs on DEBUG the
encryption parameters resolver will log what algorithms and so forth
were chosen.<br>
</body>
</html>