SAML encryption

Ramkumar Ramsubbu ramkumar.ramsubbu.consultant at nielsen.com
Thu Oct 8 12:37:03 UTC 2020


Thanks Alan for your quick response.

Just to verify, we tried to comment all the key sections in the SP Vendor
metadata file. Even then the SAML assertion was encrypted. That raised my
doubt if IDP's key is used to encrypt.

Thanks,
Ramkumar Ramasubbu
CPS



On Thu, Oct 8, 2020 at 6:00 PM Alan Buxey <alan.buxey at myunidays.com> wrote:

> hi,
> >
> > I am new to SSO implementation. We have a scenario for IDP initiated
> SSO. We shared the metadata information with our SP & we updated SP
> metadata in our idp.
> > When generating the SAML response, we see SAML assertions are encrypted
> inside the cipher data tags. I have very basic question here.
> >
> > 1. Which key is used by SSO to encrypt the saml assertion in the
> response. Is it IDP metadata key or the public key from vendor metadata ?
> > 2. We tried to decrypt with an idp private key using an online tool ,we
> got XML parse error.  Is there any way to decrypt the saml assertions we
> generate ?
>
>
> its PKI - so its encrypted in the only way that the SP can be the only
> one to read it - using the public key from the vendor metadata. only
> the SP, with their private key at the the other end, can decrypt it
>
> alan
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201008/c7c0a92b/attachment.htm>


More information about the users mailing list