
PaulT.35329 (Customer) asked a question.
I am confused by the SAML encryption settings within Okta.
If I set Assertion Encryption to Encrypted, I have to also set the Encryption Algorithm and the Key Transport Algorithm.
The Encryption Algorithm is symmetric while the Key Transport Algorithm is asymmetric.
Does this mean that a symmetric key is created by Okta, then encrypted using the SP's public key?
If so, why not just encrypt the assertion using the public key?
I could understand it would be more efficient to use symmetric encryption if messages were large or there would be many messages passed back and forth, but I don't see that being the case.
Any help appreciated,
Thanks

Hi there,
Please email your request to security@okta.com. Thank you for your understanding!