FusionAuth support for signed and encrypted assertions

66 Views Asked by At

As a SP, does FusionAuth support signed and encrypted assertions? and if so, does it require any configuration?

2

There are 2 best solutions below

0
tbg On BEST ANSWER

As of 10/23/23 and FusionAuth release 1.47.1, it appears from https://github.com/FusionAuth/fusionauth-issues/issues/2378 that FusionAuth does not support encrypted assertions as SP

1
Mark Robustelli On

Yes, FusionAuth does support signed and encrypted assertions. As of version 1.47, FusionAuth is compatible with a SAML v2 Service Provider (SP) that requires encrypted assertions. This functionality is only available when FusionAuth is acting as the SAMLv2 Identity Provider (IdP). You can enable and configure the behavior on the “SAML” tab of a given Application.

However, it's important to note that FusionAuth doesn't support "Service Provider Public Certificates" for assertion encryption at this time.

For more information, please see the FusionAuth Documentation.