Hello everyone,
I am hoping that someone can answer my question regarding CAS' signing algorithms. We are running CAS 6.1.x, and one of our SPs (Barnes and Noble's AIP) has informed us that they now support SHA256 as a signing algorithm, and want us to switch their service over to it.
I have looked at the following documentation
here and
here, which I believe are relevant. However, I still have questions that I hope someone can answer or at least point me in the right direction.
Does CAS have a default SAML2 signing algorithm or does it automatically adapt based on the service provider?
If it has a default, what is it and is there a setting to change it?
Do I just use the 'cas.authn.saml-idp.algs.override-signature-algorithms' key (which begs the question of what is it overriding)?
I hope this makes sense and I appreciate any help.
Thanks,
James