shibboleth-dev - Re: [Shib-Dev] [IdPv3] Security Config and Options
Subject: Shibboleth Developers
List archive
- From: Chad La Joie <>
- To:
- Subject: Re: [Shib-Dev] [IdPv3] Security Config and Options
- Date: Thu, 19 Aug 2010 08:48:26 -0400
- Organization: Itumi, LLC
Yeah, but you need to be careful. There are products out there that simply can't handle anything but the weakest of options. So, I'm sure when people try to ratchet up the algos they use, there will be issues.
On 8/19/10 8:40 AM, Etienne Dysli wrote:
On 06/08/10 13:46, Chad La Joie wrote:
- Expose configuration options to control crypto algorithms used
when signing and encrypting (e.g. using AES256 in signatures).
Currently the IdP uses the lowest common denominator for each option.
This was mentioned in previous email as well.
- Expose configuration options that allow certain crypto algorithms
to be blacklisted such that they will not be accepted if the SP uses
them. This allows the IdP deployer to "ban" algorithms that they feel
are too weak.
Good points. I love getting rid of the weaker ciphers were I can.
Regards,
Etienne
--
Chad La Joie
http://itumi.biz
trusted identities, delivered
- Re: [Shib-Dev] [IdPv3] Security Config and Options, (continued)
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Peter Schober, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- RE: [Shib-Dev] [IdPv3] Security Config and Options, Scott Cantor, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/06/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Etienne Dysli, 08/19/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Chad La Joie, 08/19/2010
- Re: [Shib-Dev] [IdPv3] Security Config and Options, Lukas Haemmerle, 08/06/2010
Archive powered by MHonArc 2.6.16.