In fortiauthenticator the option "Sign SAML requests with a local certificate" signs our AuthnRequest request as expected, however it does not sign the LogoutRequest, is this expected behaviour? is there anyway to make this work?
from the standard:
It is RECOMMENDED that the HTTP exchanges in this step be made over either SSL 3.0 [SSL3] or TLS 1.0 [RFC2246] to maintain confidentiality and message integrity. The message MUST be signed if the HTTP POST or Redirect binding is used. The HTTP Artifact binding, if used, also provides for an alternate means of authenticating the request issuer when the artifact is dereferenced.
Hello flamer,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
I found out that my current security team was talking to my old one when they started proposing specific ways of implementing things that I'd done previously. They didn't know why it was done like that only that "other companies are doing this".
User | Count |
---|---|
2574 | |
1373 | |
796 | |
657 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.