Re: [saml-dev] SHA-1 vs. SHA-2/SHA-3/etc.?

From
Szabó Áron <>
Date
2014-02-05T16:08:44+00:00
ID
freemail.20140205170842.57878.1@fmstatic06
Thread
Re: [saml-dev] SHA-1 vs. SHA-2/SHA-3/etc.?
Hi,

so, you mean, that in this requirement: "SAML processors SHOULD support the use of RSA signing and verification for public key operations in accordance with the algorithm identified by http://www.w3.org/2000/09/xmldsig#rsa-sha1." the "SHOULD" means that "at least, but not exclusively", am I right?

Thanks for the clarification!

Best regards,
Aron

---

You can use any algorithm you like. The SHOULD is a conformance statement
about what implementations have to support, not about what the standard
requires.