In the Signature and Encryption step, define how Federation Manager uses private keys and certificates to do the following tasks:
Note: For SAML 2.0 POST binding, you are required to sign assertions.
The certificate data store holds multiple private keys and certificates. If you have multiple federated partners, you can use a different key pair for each partner.
Note: For a Federation Manager system operating in FIPS_COMPAT or FIPS_MIGRATE mode, all certificate and key entries are available from pull-down lists. If your system is operating in FIPS-Only mode, only FIPS-approved certificate and key entries are available.
Follow these steps:
By completing this field, you are indicating which private key the asserting party uses to sign assertions, single logout requests and responses.
Note: Click Help for a description of fields, controls, and their respective requirements.
Select the algorithm that best suits your application.
RSAwithSHA256 is more secure than RSAwithSHA1 due to the greater number of bits used in the resulting cryptographic hash value.
SiteMinder uses the algorithm that you select for all signing functions.
By completing this field, you are indicating which certificate verifies signed authentication requests or single logout requests or responses. If there is no certificate in the certificate data store, import one.
Important! Signature processing must be enabled in a SAML 2.0 production environment. However, in a test environment, select the Disable Signature Processing check box to simplify testing.
Follow these steps:
This certificate encrypts assertion data. If there is no certificate in the certificate data store, import one.
Important! For the following block/key algorithm combinations, the minimum key size that is required for the certificate is 1024 bits.
Encryption Key Algorithm: RSA-OEAP
Encryption Key Algorithm: RSA-OEAP
Note: To use the AES-256 bit encryption block algorithm, install the Sun Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files. Download these files from http://java.sun.com/javase/downloads/index.jsp.
The signing and encryption configuration is complete.
| Copyright © 2012 CA. All rights reserved. |
|