Previous Topic: Protecting Federated Communication

Next Topic: Securing Connections Across the Federated Environment

Setting a One Time Use Condition for an Assertion

In compliance with the SAML 1.x and 2.0 specifications, SOA Security Manager can enforce the one time use of an assertion. By generating an assertion intended for one-time use, it tells the relying party not to retain the assertion for future transactions. Reusing an assertion beyond its validity results in authentication decisions based on out-of-date identity information.

If SOA Security Manager is acting as the asserting party (Producer/IdP), you can configure the one time use of an assertion. For a SAML 1.x affiliate, you can select the Set DoNotCache Condition setting. For a SAML 2.0 IdP, you can select the Set OneTimeUse Condition setting. Both of these configuration settings enable SOA Security Manager to insert the proper elements in an assertion that indicate the one-time use condition.

Note: Do not confuse the one time use of an assertion with the single use policy for SAML 1.x and 2.0 HTTP-POST single sign-on. The single use policy is only for POST transactions, but the one time use feature is for HTTP-Artifact and HTTP-POST.