You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
When migrating from WSO2 IS 6.0.0 to WSO2 IS 7.0.0 and SAML service providers are used. It is possible to configure the service provider certificates in the WSO2 IS keystore and set the certificate alias [1], with the option to enable signature validation for authentication and logout requests. With this configuration, WSO2 IS uses the selected certificate for request signature validation as per the provided documentation.
However, when migrating to WSO2 IS 7.0.0, the "Enable Signature Validation" option becomes tied to the certificate. As a result, even though it is possible to display the migrated certificate alias using the following configuration, updating the certificate alias causes the "Enable Signature Validation" option to be disabled.
Navigate back to the Console application, return to the SAML application, and attempt to update the certificate alias to a different one. The "Enable Signature Validation" option will be disabled.
Version
wso2is-7.0.0
Environment Details (with versions)
OS: Mac OS
Database: H2
Userstore: JDBC
The text was updated successfully, but these errors were encountered:
Description
When migrating from WSO2 IS 6.0.0 to WSO2 IS 7.0.0 and SAML service providers are used. It is possible to configure the service provider certificates in the WSO2 IS keystore and set the certificate alias [1], with the option to enable signature validation for authentication and logout requests. With this configuration, WSO2 IS uses the selected certificate for request signature validation as per the provided documentation.
However, when migrating to WSO2 IS 7.0.0, the "Enable Signature Validation" option becomes tied to the certificate. As a result, even though it is possible to display the migrated certificate alias using the following configuration, updating the certificate alias causes the "Enable Signature Validation" option to be disabled.
Since signature validation using the certificate alias is supported [1], this should be addressed in the console to ensure backward compatibility.
[1] - https://is.docs.wso2.com/en/6.0.0/guides/login/saml-app-config-advanced/#certificate-alias
Steps to Reproduce
Version
wso2is-7.0.0
Environment Details (with versions)
The text was updated successfully, but these errors were encountered: