<div dir="ltr">Hello,<div><br></div><div>We have a third party vendor which is sending a signed authentication request but with SHA1. IdP v3.3 is rejecting the request with </div><div><br></div><div><div>2017-03-10 15:22:40,716 - WARN [org.apache.xml.security.signature.XMLSignature:760] - [128.122.5.152] - Signature verification failed.</div><div>2017-03-10 15:22:40,719 - ERROR [org.opensaml.security.x509.impl.BasicX509CredentialNameEvaluator:300] - [128.122.5.152] - Credential failed name check: [subjectName='CN=*.<a href="http://taskstream.com">taskstream.com</a>,OU=Technology,O=TaskStream\, LLC,L=New York City,ST=New York,C=US']</div><div><br></div><div>Since we were able to modify the metadata we set AuthnRequestsSigned="false"</div><div><br><md:SPSSODescriptor WantAssertionsSigned="false" AuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"></div><md:KeyDescriptor use="signing"></div><div><br></div><div>but it didn't do the trick. </div><div><br></div><div>The rest of the SPs we work with and which are sending signed authn request seem to use SAH256  and there is no issues with them.  Also, IdP v3.2 has no similar problem.</div><div><br></div><div>Is SHA1 disabled in IdP v3.3 for authentication requests and if so, how we can enabled it for a particular SP?</div><div><br><div>-- <br></div><div class="gmail_signature"><div dir="ltr"><font size="2"><span title="yy27" style="padding:0px;border:0px none;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px"><span style="padding:0px;border:0px none;list-style-type:none">Yavor Yanakiev</span> </span><br style="padding:0px;border:0px none;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px"><span style="padding:0px;border:0px none;list-style-type:none;color:rgb(0,0,0);font-family:verdana,arial,helvetica,sans-serif;line-height:16px">Systems Developer for Identity Services</span></font><br><div>212-992-7585<br></div></div></div>
</div></div>