cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Guy Halse <guy AT tenet.ac.za>
- To: Matthew Slowe <Matthew.Slowe AT jisc.ac.uk>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: Re: [[cat-users]] Unable to authenticate
- Date: Thu, 6 Aug 2020 21:37:27 +0200
- Organization: Tertiary Education and Research Network of South Africa NPC
Hi
On 2020/08/06 11:46, Matthew Slowe
wrote:
I don't
know a huge amount about the inner workings of the different
algorithms, but I do wonder if SimpleSAMLphp doesn't support
"rsa-oaep" but does support "rsa-oaep-mgf1p" but, because the
first one is listed first it's using that?
Having gone through the source of robrichards/xmlseclibs v3.0.4, which is the version of the library that SimpleSAMLphp 1.18.x is using, I can confirm that it does not support/recognise rsa-oaep.
The xmlseclibs source only mentions these encryption algorithms:
- http://www.w3.org/2001/04/xmlenc#aes128-cbc
- http://www.w3.org/2001/04/xmlenc#aes192-cbc
- http://www.w3.org/2001/04/xmlenc#aes256-cbc
- http://www.w3.org/2001/04/xmlenc#tripledes-cbc
- http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p
There's no mention of http://www.w3.org/2009/xmlenc11#rsa-oaep in the source.
Support for more algorithms (including AES-GCM) is in v3.1.0 of
xmlseclibs, which is currently used by the development versions of
SSP.
--
Guy Halse
Executive Officer: Trust & Identity Tertiary Education & Research Network of South Africa NPC Fault Reporting: +27(21)763-7147 or support AT tenet.ac.za
Office: +27(21)763-7102
http://www.tenet.ac.za/contact
https://orcid.org/0000-0002-9388-8592
Executive Officer: Trust & Identity Tertiary Education & Research Network of South Africa NPC Fault Reporting: +27(21)763-7147 or support AT tenet.ac.za
Office: +27(21)763-7102
http://www.tenet.ac.za/contact
https://orcid.org/0000-0002-9388-8592
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- RE: [[cat-users]] Unable to authenticate, (continued)
- RE: [[cat-users]] Unable to authenticate, Alan Cox - UKRI, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Dubravko Penezic, 08/06/2020
- RE: [[cat-users]] Unable to authenticate, Alan Cox - UKRI, 08/07/2020
- Re: [[cat-users]] Unable to authenticate, Dubravko Penezic, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Matthew Slowe, 08/06/2020
- RE: [[cat-users]] Unable to authenticate, Alan Cox - UKRI, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Stefan Paetow, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Dubravko Penezic, 08/06/2020
- Re: [[cat-users]] Unable to authenticate, Matthew Slowe, 08/07/2020
- Re: [[cat-users]] Unable to authenticate, Matthew Slowe, 08/21/2020
- Re: [[cat-users]] Unable to authenticate, Miroslav Milinovic, 08/26/2020
- Re: [[cat-users]] Unable to authenticate, Matthew Slowe, 08/21/2020
- Re: [[cat-users]] Unable to authenticate, Matthew Slowe, 08/07/2020
- Re: [[cat-users]] Unable to authenticate, Guy Halse, 08/06/2020
- RE: [[cat-users]] Unable to authenticate, Alan Cox - UKRI, 08/06/2020
- RE: [[cat-users]] Unable to authenticate, Alan Cox - UKRI, 08/06/2020
Archive powered by MHonArc 2.6.19.