<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><meta http-equiv=Content-Type content="text/html; charset=utf-8"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
        {font-family:"Cambria Math";
        panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
        {font-family:Aptos;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
        {margin:0cm;
        font-size:12.0pt;
        font-family:"Aptos",sans-serif;
        mso-ligatures:standardcontextual;
        mso-fareast-language:EN-US;}
a:link, span.MsoHyperlink
        {mso-style-priority:99;
        color:#467886;
        text-decoration:underline;}
span.E-MailFormatvorlage17
        {mso-style-type:personal-compose;
        font-family:"Aptos",sans-serif;
        color:windowtext;}
.MsoChpDefault
        {mso-style-type:export-only;
        mso-fareast-language:EN-US;}
@page WordSection1
        {size:612.0pt 792.0pt;
        margin:70.85pt 70.85pt 2.0cm 70.85pt;}
div.WordSection1
        {page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body lang=DE link="#467886" vlink="#96607D" style='word-wrap:break-word'><div class=WordSection1><p class=MsoNormal><span style='font-size:11.0pt'>Hi,<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>I have a SP using keycloak. Since some Versions Keycloak is no longer supporting “RSA_SHA1 and DSA_SHA1 algorithms for SAML” [1].<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>I am using the default “shibboleth.EncryptionConfiguration.GCM” security configuration for my IdP. The signatures produced by this are sha512 and accepted by this SP. However the Assertions are rejected because the EncryptedKey uses the DigestMethod of “http://www.w3.org/2000/09/xmldsig#sha1” and a MGF of “http://www.w3.org/2009/xmlenc11#mgf1sha1”. <o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>Here is a Fragment from an assertion that shows that result:<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><saml2p:Response [...] ><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>    [...]<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>    <saml2:EncryptedAssertion [...]><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>        <xenc:EncryptedData [...]><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>            <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                <xenc:EncryptedKey [...]><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                    <xenc:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                                           xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                                           </span><span style='font-size:11.0pt'>><o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt'>                        <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt'>                                         xmlns:ds="http://www.w3.org/2000/09/xmldsig#"<o:p></o:p></span></p><p class=MsoNormal><span style='font-size:11.0pt'>                                         </span><span lang=EN-US style='font-size:11.0pt'>/><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                        <xenc11:MGF xmlns:xenc11="http://www.w3.org/2009/xmlenc11#"<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                                    Algorithm="http://www.w3.org/2009/xmlenc11#mgf1sha1"<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                                    /><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                    </xenc:EncryptionMethod><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                    <ds:KeyInfo><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                        <ds:X509Data><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                            <ds:X509Certificate>[...]</ds:X509Certificate><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                        </ds:X509Data><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                    </ds:KeyInfo><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                    <xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                        <xenc:CipherValue>[...]</xenc:CipherValue><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                    </xenc:CipherData><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                </xenc:EncryptedKey><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>            </ds:KeyInfo><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>            <xenc:CipherData xmlns:xenc="http://www.w3.org/2001/04/xmlenc#"><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>                <xenc:CipherValue>[...]</xenc:CipherValue><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>            </xenc:CipherData><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>        </xenc:EncryptedData><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>    </saml2:EncryptedAssertion><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'></saml2p:Response><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>I looked into the code and could not find a way to specify this in the security configuration.<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>There could be a way to specify it in the metadata but adding the following did not help:<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>  <xenc11:MGF Algorithm="http://www.w3.org/2001/04/xmlenc#MGF1withSHA256" /><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>  <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" /><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><EncryptionMethod><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>Is there another way to influence the IdP to use for example sha265 for that DigestMethod?<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>[1] <a href="https://www.keycloak.org/docs/latest/upgrading/index.html#deprecated-rsa_sha1-and-dsa_sha1-algorithms-for-saml">https://www.keycloak.org/docs/latest/upgrading/index.html#deprecated-rsa_sha1-and-dsa_sha1-algorithms-for-saml</a><o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'><o:p> </o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>With kind regards<o:p></o:p></span></p><p class=MsoNormal><span lang=EN-US style='font-size:11.0pt'>Clemens<o:p></o:p></span></p></div></body></html>