Uploaded image for project: 'RH-SSO'
  1. RH-SSO
  2. RHSSO-992

SAML Adapter fails to validate signature on encrypted assertion


      When a SAML IDP sends a signed assertion inside an encrypted assertion element, Keycloak SAML Adapter fails to validate it.
      Decryption works fine but validation afterwards fails.

      We tracked down the issue, and created a patch for it... You can find the JIRA with a link to the pull request in https://issues.jboss.org/browse/KEYCLOAK-4897

      This blocks our adoption of the SSO version since we only use encrypted assertions, so without it nothing works. As long as this patch is not in the mailine, we need to remain with the patched community version.

            mhajas@redhat.com Michal Hajas
            rhn-support-igueye Issa Gueye
            0 Vote for this issue
            5 Start watching this issue
