Werk #15448: SAML: response signature is optional

Komponente Setup, site management
Titel SAML: response signature is optional
Datum 22.03.2023
Level Kleine Änderung
Klasse Neues Feature
Kompatibilität Kompatibel - benötigt kein manuelles Eingreifen
Checkmk versions & editions
2.3.0b1 Checkmk Enterprise (CEE), Checkmk Cloud (CCE), Checkmk MSP (CME)
2.2.0b1 Checkmk Enterprise (CEE), Checkmk Cloud (CCE), Checkmk MSP (CME)

Checkmk required both the response and the assertion statement to be signed in order to accept an authentication request response from the identity provider. However, as per the SAML specifications, only the assertion statement signature is required and the response signature is optional. For this reason, authentication request responses that only have the assertion statement signed are now accepted.

See section 4.1.3.5 in: http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf

Zur Liste aller Werks