<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y0000ABUiQ6SQLOkta Classic EngineSingle Sign-OnAnswered2024-03-25T18:02:17.000Z2021-01-05T09:47:43.000Z2021-01-07T00:12:18.000Z

b6nnt (b6nnt) asked a question.

Does OKTA Validate Signature on SAML Authentication Requests

I found an article which is older. Wanted to know Does OKTA Validate Signature on SAML Authentication Requests on latest version of okta?

https://support.okta.com/help/s/question/0D50Z00008C3jZLSAZ/does-okta-validate-signature-on-saml-authentication-requests?language=en_US

 

By default OKTA is not supporting request signing, confirmed this through the request created and traced via SAML tracer.

 

SIgnature and SigAlg parameters in Parameters of SAML tracer is not seen

 

Image is not available

 

 


  • Hi @b6nnt (b6nnt)​,

     

    Thank you for posting your inquiry to Okta Support Community Portal.

     

    Okta currently doesn't validate AuthnRequest signatures, this is expected behavior.

     

    In a SP-Initated flow, the SP generates an AuthnRequest that is sent to the Okta as the first step in the process and Okta then responds with a SAML Response. 

     

    If you would like to see such functionality in Okta the best route to pursue this is via a feature request. This can be done on the Okta Community page by using the 'Feedback' option at the bottom of the Okta admin console, once on the Community page go to Ideas -> Post Idea. Features suggested in our community are reviewed and can be voted and commented on by other members of the community, therefore making it much easier for the engineering team to understand the priorities that you have for feature requests.

     

    Best Regards,

     

    Catalin

    Expand Post
This question is closed.
Loading
Does OKTA Validate Signature on SAML Authentication Requests