Validate signature in identity provider configuration not working properly.
Issue
Validate signature
inidentity provider
configuration inRHSSO
not working as expected.- There are two
RHSSO
instances in different environments, where one (let’s call it Alice) acts as theIdentity Provider
for the other (Boris).Boris
is configured to haveAlice
as itsSAML Identity Provider
, while Alice listsBoris
as one of itsSAML client
.
SetSign Documents
andSign assertions
toFALSE
inAlice
and makeValidate Signature
toTRUE
andWant Assertions signed
toFALSE
in Boris.
In this case, the SAML-Response fromAlice
is accepted byBoris
, despite the fact that Boris is supposed to validate a signature.
Checking the SAML-response issued byAlice
revealed that no signature was present in the document.
Environment
- Red Hat Single Sign-On (RHSSO)
- All versions
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.