<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 7/6/16 5:40 PM, Cantor, Scott wrote:<br>
    </div>
    <blockquote
cite="mid:9846A6064BD102419D06814DD0D78DE11298BFD2@CIO-TNC-D2MBX02.osuad.osu.edu"
      type="cite"><br>
      <pre wrap="">I don't think we're using GCM by default for XML Encryption though, are we? </pre>
    </blockquote>
    <br>
    Not by default, but it would if the metadata said to via the
    algorithm extensions (which I think the Shib SP metadata does by
    default IIRC) and it was supported by the platform (security
    providers).<br>
    <br>
    <blockquote
cite="mid:9846A6064BD102419D06814DD0D78DE11298BFD2@CIO-TNC-D2MBX02.osuad.osu.edu"
      type="cite">
      <pre wrap="">In fact, GCM didn't even work properly with Java 7's JCE, that I recall.</pre>
    </blockquote>
    <br>
    I'm not sure, I can't keep them straight. It might not with Oracle's
    default security provider set (although I could be wrong), but
    pretty sure it does with BC configured.<br>
    <br>
    <br>
    If there's any question, earlier on in the logs on DEBUG the
    encryption parameters resolver will log what algorithms and so forth
    were chosen.<br>
  </body>
</html>