Skip to main content

SAML2SSOProfile

Definition

This is the most common used SAML profile. It allows the IdP to identify users and to give such information to Service Providers. 

Screen overview

&&TODO&&

Standard attributes

  • Sign Responses: a sign response guarantees the service provider that the response has been issued by the Identity Provider &&TODO&&
    • Conditional ¿Como funciona?
    • Always
    • Never
    •  
  • Sign Assertions: it's advisable to sign every assertion, so it avoids assertion spoofing. &&TODO&&
  • Sign Assertions &&TODO&&
  • Encrypt Assertions: it's a good practice to encrypt assertions. Nevertheless, it makes more dificult to diagnose misconfiguration of SAML federation. Disable it only when needed.
  • Encrypt NameIds: encrypt Name Ids when they are not part of an assertion.
  • Assertion Proxy Count: number of SAML proxies that can forward an assertion. 0 stands for no limit.
  • Include Attribute Statement: on a SSO profile will give the service provider every attribute bound to the identified user, avoid the need for extra attribute requests.
    • Include Attribute Statement : &&TODO&& este es un campo de texto debajo del check anterior