<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;">
<div style="font-family: Calibri, sans-serif; font-size: 14px; color: rgb(0, 0, 0);">
Greetings,</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; color: rgb(0, 0, 0);">
We’ve cutover our IdP from v2 to v3.2.1. One of our internal SP’s have an outdated openssl library:</div>
<div>
<p style="font-family: Monaco; font-size: 10px; margin: 0px; line-height: normal;">
2016-10-11 11:05:07 DEBUG XMLTooling.TrustEngine.PKIX [4]: Caught an XMLSecurity exception verifying signature: OpenSSL:Hash - SHA256 not supported by this version of OpenSSL</p>
<p style="font-family: Monaco; font-size: 10px; margin: 0px; line-height: normal;">
<br>
</p>
<p style="margin: 0px; line-height: normal;"><font face="Calibri,sans-serif">Unfortunately the SP is running end-of-life RHEL4 so there is no updates to openssl. The folks that manage this system say they are unable to migrate to a newer redhat in the short
term. Is there a way in IdP to sign using SHA1 just for this SP?</font></p>
<p style="margin: 0px; line-height: normal;"><font face="Calibri,sans-serif"><br>
</font></p>
<p style="margin: 0px; line-height: normal;"><font face="Calibri,sans-serif">R</font><font face="Calibri,sans-serif">egards,</font></p>
<p style="margin: 0px; line-height: normal;"><font face="Calibri,sans-serif">Ryan</font></p>
</div>
<div style="font-family: Calibri, sans-serif; font-size: 14px; color: rgb(0, 0, 0);">
<div id="MAC_OUTLOOK_SIGNATURE"></div>
</div>
</body>
</html>