<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000668rU2SAIOkta Classic EngineIntegrationsAnswered2019-04-01T08:00:44.000Z2019-03-29T11:01:44.000Z2019-04-01T08:00:44.000Z
How does Okta use symmetric encryption with SAML?

I am confused by the SAML encryption settings within Okta.

If I set Assertion Encryption to Encrypted, I have to also set the Encryption Algorithm and the Key Transport Algorithm.

The Encryption Algorithm is symmetric while the Key Transport​ Algorithm is asymmetric.

Does this mean that a symmetric key is created by Okta, then encrypted using the SP's public key?

If so, why not just encrypt the assertion using the public key?

I could understand it would be more efficient to use symmetric encryption if messages were large or there would be many messages passed back and forth, but I don't see that being the case.

 

Any help appreciated,

Thanks


This question is closed.
Loading
How does Okta use symmetric encryption with SAML?