Improvements in SAML Authentication
-
SAML Service Provider (SP)
-
SAML Identity Provider (IdP)
Solution
-
SAML SP Post Binding – Signing of AuthnRequest
-
SAML IdP Post Binding – Signing of Assertion/Response/Both
-
SAML SP Single Logout scenarios – Signing of LogoutRequest in SP initiated model and Signing of LogoutResponse in IdP initiated model
-
SAML SP Artifact binding – Signing of ArtifactResolve request
-
SAML SP Redirect Binding – Signing of AuthnRequest
-
SAML IdP Redirect Binding – Signing of Response/Assertion/Both
-
SAML SP Encryption support – Decryption of Assertion
Platform
Configuration
-
add ssl fipsKey fips-keyCreate a CSR and use it at the CA server to generate a certificate. You can then copy that certificate in/nsconfig/ssl. Let’s assume that the file is fips3cert.cer. -
add ssl certKey fips-cert -cert fips3cert.cer -fipsKey fips-keyThen specify this certificate in the SAML action for the SAML SP module. -
set samlAction <name> -samlSigningCertName fips-certLikewise, you use this in thesamlIdpProfilefor the SAML IdP module. -
set samlidpprofile fipstest –samlIdpCertName fips-cert
create ssl fipskey <fipsKeyName> -modulus <positive_integer> [-exponent (3 | F4)]
create certreq <reqFileName> -fipskeyName <string>