Encrypted SAML Assertions
Encrypted SAML assertions are a compliance standard in many industries and mitigate the risk of intercepted SAML assertions.
- Secure Access requires encryption of the whole SAML assertion. Secure Access does not support configuring the IdP to specify EncryptedAttribute or EncryptedID.
- Secure Access requires SAML assertions encrypted using the key downloaded from Connect > Users and Groups > Configuration Management.
- Secure Access requires SAML assertions encrypted in sign-then-encrypt order, and will not support SAML assertions encrypted in encrypt-then-sign order.