Skip to Content.

edugain-discuss - Re: [eduGAIN-discuss] Cryptographic strength of UK federation eduGAIN upstream

edugain-discuss AT lists.geant.org

Subject: An open discussion list for topics related to the eduGAIN interfederation service.

List archive


Re: [eduGAIN-discuss] Cryptographic strength of UK federation eduGAIN upstream


Chronological Thread 
  • From: Peter Brand <peter.brand AT univie.ac.at>
  • To: edugain-discuss AT lists.geant.org
  • Subject: Re: [eduGAIN-discuss] Cryptographic strength of UK federation eduGAIN upstream
  • Date: Sat, 4 Jun 2022 16:30:41 +0200

* Alex Stuart <Alex.Stuart AT jisc.ac.uk> [2022-06-03 16:48]:
> We in the UK federation team are reviewing the cryptographic
> strength of our metadata publication service. Integrity &
> authenticity of our aggregates (including our eduGAIN upstream feed)
> is provided by a 2K RSA key, SHA-256 signature and digest
> algorithms.

Note that your (or anyone's) eduGAIN upstream feed is the least of
your concerns here as it should be able to be changed at any time,
really, involving only the eduGAIN Operations Team and your own
signing infrastructure.

(E.g. I've changed to using SHA-256 with our eduGAIN upstream long
before adopting this with our downstream feeds, due to known or
suspected incompatibilities with legacy systems in use throughout our
communities.)

-peter



Archive powered by MHonArc 2.6.19.

Top of Page