4.3.17 Ensure 'authnRequestsSigned' is set to 'true' in SAML

Information

SAML providers can sign the request messages for authenticity.

SAML authentication request messages ( <samlp:AuthnRequest> messages) can be signed so it can be verified securely by the receiver.

Solution

Add the authnRequestsSigned attribute to all samlWebSso20 elements to ${server.config.dir}/configDropins/overrides/*.xml and set it to true

<samlWebSso20 ...
authnRequestsSigned="true"
/>

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-3

Plugin: Unix

Control ID: 297c9ca53250ab71593ec251ba40d21e156eb119c2be9c6d76dad23d9e843d48