Fortinet white logo
Fortinet white logo

Administration Guide

SAML Authentication Request Signing Support (8.0.3)

SAML Authentication Request Signing Support (8.0.3)

FortiWeb 8.0.3 introduces support for signing SAML Authentication Requests when FortiWeb is operating as a Service Provider (SP). This enhancement allows FortiWeb to attach a digital signature to each AuthnRequest sent to the Identity Provider (IdP), improving interoperability with IdPs that require signed requests and strengthening the integrity and trust validation of the SAML authentication flow.

When enabled, FortiWeb signs outgoing requests using a selected SP certificate, and the IdP validates the signature to ensure that only trusted authentication requests are accepted.

Configuration Update

In Security Fabric > Fabric Connectors > Security Fabric Setup, the Single Sign-On Settings now include a new option when FortiWeb is configured as a Service Provider (SP):

Parameter

Description

Authentication Request Signed Enables FortiWeb to sign SAML authentication requests using the selected SP certificate. Disabled by default.

Enabling this option requires an imported SP certificate, and the Identity Provider must be configured to verify the signature.

SAML Authentication Request Signing Support (8.0.3)

SAML Authentication Request Signing Support (8.0.3)

FortiWeb 8.0.3 introduces support for signing SAML Authentication Requests when FortiWeb is operating as a Service Provider (SP). This enhancement allows FortiWeb to attach a digital signature to each AuthnRequest sent to the Identity Provider (IdP), improving interoperability with IdPs that require signed requests and strengthening the integrity and trust validation of the SAML authentication flow.

When enabled, FortiWeb signs outgoing requests using a selected SP certificate, and the IdP validates the signature to ensure that only trusted authentication requests are accepted.

Configuration Update

In Security Fabric > Fabric Connectors > Security Fabric Setup, the Single Sign-On Settings now include a new option when FortiWeb is configured as a Service Provider (SP):

Parameter

Description

Authentication Request Signed Enables FortiWeb to sign SAML authentication requests using the selected SP certificate. Disabled by default.

Enabling this option requires an imported SP certificate, and the Identity Provider must be configured to verify the signature.