Validate signature in identity provider configuration not working properly.
Issue
Validate signatureinidentity providerconfiguration inRHSSOnot working as expected.- There are two
RHSSOinstances in different environments, where one (let’s call it Alice) acts as theIdentity Providerfor the other (Boris).Borisis configured to haveAliceas itsSAML Identity Provider, while Alice listsBorisas one of itsSAML client.
SetSign DocumentsandSign assertionstoFALSEinAliceand makeValidate SignaturetoTRUEandWant Assertions signedtoFALSEin Boris.
In this case, the SAML-Response fromAliceis accepted byBoris, despite the fact that Boris is supposed to validate a signature.
Checking the SAML-response issued byAlicerevealed that no signature was present in the document.
Environment
- Red Hat Single Sign-On (RHSSO)
- All versions
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.