<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic (ADFS) SP-Initiated Single Logout (SLO) / SHA256 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/adfs-sp-initiated-single-logout-slo-sha256/m-p/3526792#M519105</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, is ISE going to support SHA256 to do SLO in the next releases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now we have this info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"For this to work we need to set the secure hash algorithm to SHA1 instead of the default SHA-256.&lt;/P&gt;&lt;P&gt;This is set in ISE relying party trust properties under advanced.&lt;/P&gt;&lt;P&gt;If you don’t set this you’ll get the following message in to the ADFS event log:&lt;/P&gt;&lt;P&gt;Event ID: 378&lt;/P&gt;&lt;P&gt;SAML request is not signed with expected signature algorithm. SAML request is signed with&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;signature algorithm &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" rel="nofollow" target="_blank"&gt;http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&lt;/A&gt;&lt;SPAN&gt; . Expected signature&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;algorithm is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.w3.org/2000/09/xmldsig#rsa-sha1" rel="nofollow" target="_blank"&gt;http://www.w3.org/2000/09/xmldsig#rsa-sha1&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 14 Dec 2017 15:10:04 GMT</pubDate>
    <dc:creator>atapiafl@cisco.com</dc:creator>
    <dc:date>2017-12-14T15:10:04Z</dc:date>
    <item>
      <title>(ADFS) SP-Initiated Single Logout (SLO) / SHA256</title>
      <link>https://community.cisco.com/t5/network-access-control/adfs-sp-initiated-single-logout-slo-sha256/m-p/3526792#M519105</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, is ISE going to support SHA256 to do SLO in the next releases?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now we have this info:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"For this to work we need to set the secure hash algorithm to SHA1 instead of the default SHA-256.&lt;/P&gt;&lt;P&gt;This is set in ISE relying party trust properties under advanced.&lt;/P&gt;&lt;P&gt;If you don’t set this you’ll get the following message in to the ADFS event log:&lt;/P&gt;&lt;P&gt;Event ID: 378&lt;/P&gt;&lt;P&gt;SAML request is not signed with expected signature algorithm. SAML request is signed with&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;signature algorithm &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" rel="nofollow" target="_blank"&gt;http://www.w3.org/2001/04/xmldsig-more#rsa-sha256&lt;/A&gt;&lt;SPAN&gt; . Expected signature&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;algorithm is &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.w3.org/2000/09/xmldsig#rsa-sha1" rel="nofollow" target="_blank"&gt;http://www.w3.org/2000/09/xmldsig#rsa-sha1&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adfs-sp-initiated-single-logout-slo-sha256/m-p/3526792#M519105</guid>
      <dc:creator>atapiafl@cisco.com</dc:creator>
      <dc:date>2017-12-14T15:10:04Z</dc:date>
    </item>
    <item>
      <title>Re: (ADFS) SP-Initiated Single Logout (SLO) / SHA256</title>
      <link>https://community.cisco.com/t5/network-access-control/adfs-sp-initiated-single-logout-slo-sha256/m-p/3526793#M519108</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please work with the ISE product managers on features. We don’t discuss futures in public forum&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Dec 2017 15:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/adfs-sp-initiated-single-logout-slo-sha256/m-p/3526793#M519108</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-14T15:25:30Z</dc:date>
    </item>
  </channel>
</rss>

