<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
Heh, yes, sadly, while I tried explaining that to them, it fell on deaf ears. They acknowledged they could accept our SHA1 MD RSA2048 cert, and I thought we were done. THEN, they asked our legal department to sign a document stating that we accept / absolve
 them of any responsibility should there be a data privacy violation... soooo, in the interest of not tilting at windmills more than I already do, I decided to acquiesce.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
Thanks Scott for pointing out my error! Indeed, I didn't have all the parts connected. It's working well now, and if this should come up again in the future, we can handle it without trying to lecture them on cryptographic basics.</div>
<div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div id="Signature">
<div id="divtagdefaultwrapper" dir="ltr" style="font-family: Calibri, Arial, Helvetica, sans-serif, EmojiFont, "Apple Color Emoji", "Segoe UI Emoji", NotoColorEmoji, "Segoe UI Symbol", "Android Emoji", EmojiSymbols; font-size: 12pt; color: rgb(0, 0, 0); background-color: rgb(255, 255, 255);">
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="#a00000" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><strong style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">David
 Mak</span></strong></span></font></span></font></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="#a00000" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><strong style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">Identity
 Services Specialist</span></strong></span></font></span></font></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="black" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">Information
 Technology Services</span></span></font></span></font></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="black" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"></span></span></font></span></font><span style="font-size: 10pt; color: black;">Northeastern
 University</span></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="black" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">360
 Huntington Ave. Boston MA 02115-5000</span></span></font></span></font></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="black" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">Mail
 Stop: 322-C21</span></span></font></span></font></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<font style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:10pt"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="black" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">O:617-373-7836
 M:617-840-7543</span></span></font></span></font></div>
<div style="margin: 0px; color: rgb(33, 33, 33); background-color: rgb(255, 255, 255);">
<span style="font-size:10pt"><font style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><font color="black" style="font-family: Calibri, Arial, Helvetica, sans-serif;" data-ogsc=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"></span></font></span></font><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"></span></span><a href="mailto: d.mak@neu.edu" style=""><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">d.mak</span></span><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">@northeastern.ed</span></span><span style="font-family:Calibri,Arial,Helvetica,sans-serif"><span style="font-family:Calibri,Arial,Helvetica,sans-serif">u</span></span></span></span></a></span></div>
</div>
</div>
</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Peter Schober <peter.schober@univie.ac.at><br>
<b>Sent:</b> Friday, May 29, 2020 5:58 AM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Configuring additional signing/encryption certificate/key pairs for IDP 3.4.6</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt;">
<div class="PlainText">* Mak, David <d.mak@northeastern.edu> [2020-05-28 23:33]:<br>
> We have a vendor who is complaining about a SHA1 signed RSA2048 self<br>
> signed cert (not due to expire until 2032) and how they need to<br>
> configure an exception to accept our signed responses (that they<br>
> require) so we looked into creating a new SHA256 MD/signed RSA2048<br>
> cert and added it as per:<br>
<br>
Not that this will matter much but that means they have a bug, no?<br>
(Just so that we're clear about this at least here.)<br>
<br>
The signature on a self-signed certificate by its nature is<br>
meaningless (because its self-asserted so provides no more information<br>
nor trust than what's being signed), so is the signature algorithm<br>
used in that signature.<br>
<br>
The only useful thing in such a certificate is the public key itself<br>
and it's trustworthy only because of trustworthy exchange of the SAML<br>
2.0 metadata its embedded into.<br>
<br>
<a href="https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.oasis-open.org%2Fsecurity%2FSAML2MetadataIOP&amp;data=02%7C01%7Cd.mak%40northeastern.edu%7C35fed3d5e3584606809308d803b6e969%7Ca8eec281aaa34daeac9b9a398b9215e7%7C0%7C0%7C637263431425728553&amp;sdata=WYyECmf9gQWZjZjQxdYHYU5SMlBx9D0YlL4NI77OHE4%3D&amp;reserved=0">https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.oasis-open.org%2Fsecurity%2FSAML2MetadataIOP&amp;data=02%7C01%7Cd.mak%40northeastern.edu%7C35fed3d5e3584606809308d803b6e969%7Ca8eec281aaa34daeac9b9a398b9215e7%7C0%7C0%7C637263431425728553&amp;sdata=WYyECmf9gQWZjZjQxdYHYU5SMlBx9D0YlL4NI77OHE4%3D&amp;reserved=0</a><br>
<br>
If so you should be telling the vendor that so that maybe they could<br>
fix this and spare other customers to perform the dance you're now<br>
having to go through to work around their bug.<br>
<br>
Best,<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&amp;data=02%7C01%7Cd.mak%40northeastern.edu%7C35fed3d5e3584606809308d803b6e969%7Ca8eec281aaa34daeac9b9a398b9215e7%7C0%7C0%7C637263431425728553&amp;sdata=uMOrlAr9bIiGN2vnsjrFIx0nRK%2FAWaoXoWOzeRcg%2BYM%3D&amp;reserved=0">
https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fx%2FcoFAAg&amp;data=02%7C01%7Cd.mak%40northeastern.edu%7C35fed3d5e3584606809308d803b6e969%7Ca8eec281aaa34daeac9b9a398b9215e7%7C0%7C0%7C637263431425728553&amp;sdata=uMOrlAr9bIiGN2vnsjrFIx0nRK%2FAWaoXoWOzeRcg%2BYM%3D&amp;reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</body>
</html>