Federation Security Services Guide › Deploy Federation Using a Manual Configuration › Add Functionality to the Federation Deployment › Configure Digital Signing (required for POST Binding) › Enable Signature Validation at the SP
Enable Signature Validation at the SP
To validate a digital signature for POST single sign-on
- Log in to the FSS Administrative UI.
- From the System tab, select Authentication Schemes to display the Authentication Scheme List.
Select the existing SAML 2.0 authentication scheme, Partner IdP.demo Auth Scheme
The Authentication Scheme Properties dialog opens.
- In the Scheme Common Setup section, clear the Disable Signature Processing. Disabling this option enables signature processing.
- In the D-Sig Info box, enter the following:
- Issuer DN
-
CN=Certificate Manager,OU=IAM,O=CA.COM
- Serial Number
-
008D 8B6A D18C 46D8 5B
The D-Sig information enables the Service Provider to verify the SAML response signature. The values for the Issuer DN and Serial Number are from the public key in the smkeydatabase of the Service Provider.
- Click OK.
Validation configuration is now complete.
- Test POST single sign-on.
Copyright © 2012 CA.
All rights reserved.
|
|