FIM - Can FIM create SAML assertions signed with SHA256 instead of SHA1?
Originally Published: 2014-01-24
Article Number
Applies To
Issue
Can FIM be forced to create SAML assertions signed with SHA256 instead of SHA1? The SAML specs only mention SHA1 .
Resolution
FIM doesn??t have capability to select higher strength algorithms??
It supports only following algorithms depending upon the key algorithm of keystore available for signing.
DSA: ??http://www.w3.org/2000/09/xmldsig#dsa-sha1??
RSA: ??http://www.w3.org/2000/09/xmldsig#rsa-sha1??
The SAML spec :
5.4.1 Signing Formats and Algorithms
SAML processors SHOULD support the use of RSA signing and verification for public key
operations in accordance with the algorithm identified by http://www.w3.org/2000/09/xmldsig#rsa-sha1.
Related Articles
Agent Auto-Registration 97Number of Views Long URL's cause a the 4.8 Agent for IIS 7 to crash 9Number of Views Upgrading the RSA Authentication Agent for Windows certificates to SHA-256 for offline authentication and agent auto-regis… 785Number of Views Upgrading the Internal SecurID Authentication Manager 8.6 Certificates to SHA-256 522Number of Views The January and March 2020 Appliance Updaters fail and prevent the Database from starting up in RSA Identity Governance & … 211Number of Views
Don't see what you're looking for?