Azure-docs: Signed SAML requests

Created on 16 Oct 2018  Â·  3Comments  Â·  Source: MicrosoftDocs/azure-docs

Hi,

Is it possible for the application to send signed saml requests? Where can i configure the certificate, so that azure ad can validate the signature on the request?

I read in a forum that azure ad ignores signatures on SAML requests. If that is true, it should be mentioned in the docs. (And why this is safe?)

Thanks,
Martin


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

active-directorsvc cxp in-progress product-question triaged

All 3 comments

@mrmueller
Thanks for your feedback! We will investigate and update as appropriate.

@mrmueller Please check on this document Single Sign-On SAML protocol, in this section - Signature it states that - _Don't include a Signature element in AuthnRequest elements, as Azure AD does not support signed authentication requests._

Thanks for your response. This helps a lot.
Still, it would be great to know if azure just ignores the signature or if something will break and what the security implications of doing without a signature are.

Thanks again

Was this page helpful?
0 / 5 - 0 ratings

Related issues

JeffLoo-ong picture JeffLoo-ong  Â·  3Comments

jharbieh picture jharbieh  Â·  3Comments

behnam89 picture behnam89  Â·  3Comments

spottedmahn picture spottedmahn  Â·  3Comments

monteledwards picture monteledwards  Â·  3Comments