Next in thread → Next in month →

Re: [saml-dev] using HMAC-SHA1 as for SSO (SAML)

From
Cantor, Scott <>
Date
2012-03-10T07:52:02+00:00
ID
Thread
Re: [saml-dev] using HMAC-SHA1 as for SSO (SAML)
On 3/8/12 8:28 PM, "" <> wrote:
>
>We have a customer who wants to use
>HMAC-SHA1 (with a shared symmetric key) as digital signature vs our
>standard
>RSA-SHA1, we are trying to see if SAML spec allows it.

It allows anything XML Signature allows, essentially.

> 
> 
>Obviously HMAC-SHA1 is faster but since
>I am not a crypto person, it is hard for me to tell the customer if there
>is any security vulnerability at the crypto level.  We know it provide
>integrity, some level of authentication, can it provide non reputation
>for auditing purpose ?

I would assume not, since obviously the RP has the same key.

-- Scott
Next in thread → Next in month →