<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#FFFFFF" text="#000000">
    <p><br>
    </p>
    <br>
    <div class="moz-cite-prefix">On 7/13/16 2:32 AM, Muthuraman
      Sethuraman Sethuraman (US - Advisory) wrote:<br>
    </div>
    <blockquote
cite="mid:CAHyMKnQ5EKoVyNZEjiLkbjvOKQuVestWUihyqxN77piOGFBQZg@mail.gmail.com"
      type="cite">
      <div dir="ltr">
        <p class="MsoNormal" style="font-size:12.8px"><span
            style="color:rgb(31,73,125)" lang="EN-US">Netscaler SP is
            not supporting SHA512 algorithms yet.</span></p>
        <span style="color:rgb(31,73,125)" lang="EN-US"> </span>
        <p class="MsoNormal" style="font-size:12.8px"><font
            color="#1f497d">Is there a way i can configure Shibboleth
            IDP 3.2.1 to use sha256 algorithm to sign the response.</font></p>
      </div>
    </blockquote>
    <br>
    <br>
    Well, the out-of-the-box IdP v3 default is actually SHA-256.  So
    unless you specifically 
    configured for SHA-512, I think the only way this could happen is if
    the SP's metadata says to do SHA-512. The stated preferences of the
    SP in its metadata will override the IdP configuration.<br>
    <br>
    So check that. If Netscaler themselves gave you their metadata, or
    you're getting it from a metadata publisher, etc, then it's just
    wrong and you should tell them.  If this is a case where you had to
    construct the SP metadata yourself in order to feed to the IdP, then
    you just need to remove or re-order the algorithms listed in the
    Extensions element.<br>
    <br>
  </body>
</html>