Skip to content

PySAML2 not using signing_algorithm from sp service #963

Description

@openbrian

sp specific algorithms not being used

Code Version

7.4

Expected Behavior

https://pysaml2.readthedocs.io/en/latest/howto/config.html#signing-algorithm should be used as demonstrated.

Current Behavior

The default algorithm is used. This is sha1. Sha1 in FIPS mode (openssl) is not permitted. xmlsec1 will crash or error out. I'll put error messages in a comment.

Possible Solution

In Entity constructor, when getting the algorithms from the config, include the context which is self.entity_type.

Or, alter config getattr such that if context is specified, look there first. If the attribute is not there, then look it up (inherit) from one level up.

And/Or, drop the {context}{attr}, and stick with nested dictionaries.

Or, set the default algorithm to be anything but sha1 which is considered insecure.

Steps to Reproduce

Use PySAML2 with OpenSSL in FIPS mode. Otherwise pretty generic config. set authn_requests_signed to true.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions