go-saml icon indicating copy to clipboard operation
go-saml copied to clipboard

sign AuthnRequests and AuthnResponses with SHA256

Open mattg-sigsci opened this issue 5 years ago • 3 comments

SHA1 is vulnerable so better to use SHA256 instead

mattg-sigsci avatar Jul 10 '20 16:07 mattg-sigsci

👋 @mattg-sigsci is this going to be merged? we (at snyk) plan to add this issue to our vulnerability db when but can wait until it is mitigated.

gurshafriri avatar Aug 04 '20 11:08 gurshafriri

@gurshafriri I don't know. It doesn't seem like RobotsAndPencils is maintaining this library. We're not using this fork anymore. Maybe one of the other forks is more maintained, perhaps Cloudflare's?

mattg-sigsci avatar Aug 04 '20 14:08 mattg-sigsci

Hello @mbrevoort since there are some security concern, can you please give us some of your time for review this PR and bring it into the repository? Thanks!

bestbug456 avatar Jan 19 '23 08:01 bestbug456