Version Affected: All
Bug Number: EE-3582
Bug Status: Closed - Fixed
Fixed in Version(s): 22.12 HF13+, 24.4 RU4+
Overview
This article explains why the WantAuthNRequestsSigned value in the SAML Metadata.xml file cannot be set independently of other settings, even though some Service Providers require this value to be a specific setting (true or false).
Cause
On a Classic realm, downloading the Metadata.xml file from Advanced Settings always generates WantAuthNRequestsSigned as 0. No realm configuration change affects this, since the value is hardcoded.
On a New Experience realm, downloading the Metadata.xml file from Advanced Settings behaves the same way as a Classic realm. Downloading it from the New Experience interface instead, the value follows the Sign SAML Assertion setting: WantAuthNRequestsSigned is set to true if Sign SAML Assertion is enabled, and false if it is disabled. WantAuthNRequestsSigned should be independently configurable and should not depend on whether the Identity Platform signs the SAML assertion.
Resolution / Workaround
Upgrade to version 22.12 HF13 or later, or 24.4 RU4 or later, to resolve this issue.
If you cannot upgrade immediately, as a workaround, manually edit the downloaded Metadata.xml file to set WantAuthNRequestsSigned to the value required by the Service Provider.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.