<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML AuthRequest assertions are not signed by the ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435514#M517684</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked these 2 documents - &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-64012"&gt;ISE Design &amp;amp;amp; Integration Guides&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-69125"&gt;Lab Config Guide: ISE 2.1 with Ping Fed for Guest Web Auth &amp;amp;amp; Sponsor Portal SAML SSO&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;meanwhile I have asked our SME to look into it .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Feb 2018 13:26:30 GMT</pubDate>
    <dc:creator>Nidhi</dc:creator>
    <dc:date>2018-02-23T13:26:30Z</dc:date>
    <item>
      <title>SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435512#M517681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My customer raised a question about SAML assertions signature. They confirmed that in their integration with Identity Federation the SAML AuthRequest is not signed by ISE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE class="hist-break-word con-NoMargin"&gt;&amp;lt;samlp:AuthnRequest xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL=" &lt;A href="https://mydevices.par.michelin.com:8444/mydevicesportal/SSOLoginResponse.action&amp;quot;" target="_blank" title="https://mydevices.par.michelin.com:8444/mydevicesportal/SSOLoginResponse.action&amp;quot;"&gt;https://mydevices.example.com:8444/mydevicesportal/SSOLoginResponse.action"&lt;/A&gt;; ForceAuthn="false" ID="_94996df0-0a98-11e8-9ab8-380e4d172cf6_DELIMITERportalId_EQUALS94996df0-0a98-11e8-9ab8-380e4d172cf6_SEMIportalSessionId_EQUALSe8349759-d271-40dd-b6a7-9e9b77fe9d31_SEMI_DELIMITERmydevices.par.michelin.com" IsPassive="false" IssueInstant="2018-02-14T16:42:57.491Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0" Cacher le texte cité &amp;gt; &amp;lt;samlp:Issuer xmlns:samlp="urn:oasis:names:tc:SAML:2.0:assertion"&amp;gt;http://CiscoISE/94996df0-0a98-11e8-9ab8-380e4d172cf6&amp;lt;/samlp:Issuer&amp;gt; &amp;lt;saml2p:NameIDPolicy xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" AllowCreate="false" /&amp;gt; &amp;lt;saml2p:RequestedAuthnContext xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" Comparison="exact" Cacher le texte cité &amp;gt; &amp;lt;saml:AuthnContextClassRef xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"&amp;gt;urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport&amp;lt;/saml:AuthnContextClassRef&amp;gt; &amp;lt;/saml2p:RequestedAuthnContext&amp;gt; &amp;lt;/samlp:AuthnRequest&amp;gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I haven't found any documentation on the matter. Could you please tell me if this is expected and if we can force the signature in any way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mateusz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2018 08:08:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435512#M517681</guid>
      <dc:creator>mtrojcza</dc:creator>
      <dc:date>2018-02-22T08:08:11Z</dc:date>
    </item>
    <item>
      <title>Re: SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435513#M517683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reasearching &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Feb 2018 15:05:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435513#M517683</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-02-22T15:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435514#M517684</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you checked these 2 documents - &lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-64012"&gt;ISE Design &amp;amp;amp; Integration Guides&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/docs/DOC-69125"&gt;Lab Config Guide: ISE 2.1 with Ping Fed for Guest Web Auth &amp;amp;amp; Sponsor Portal SAML SSO&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;meanwhile I have asked our SME to look into it .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Nidhi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:26:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435514#M517684</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2018-02-23T13:26:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435515#M517686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nidhi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for looking into it. Yes, I have checked the docs you mentioned, but didn't find the level of details needed to answer these doubts...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will be looking forward to hearing from the SME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mateusz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 13:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435515#M517686</guid>
      <dc:creator>mtrojcza</dc:creator>
      <dc:date>2018-02-23T13:33:08Z</dc:date>
    </item>
    <item>
      <title>Re: SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435516#M517688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Below is to re-iterate what we discussed:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At present, it's not configurable in ISE to sign SAML AuthRequest. Logout requests are the ones with the option to be signed in the SAML advanced settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/SAML_2.0#HTTP_Redirect_Binding"&gt;3.1 HTTP Redirect Binding in SAML 2.0 - Wikipedia&lt;/A&gt; says&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;… In practice, all the data contained in a &amp;lt;samlp:AuthnRequest&amp;gt;, such as Issuer which contains the SP ID, and NameIDPolicy, has been agreed between IdP and SP beforehand (via manual information exchange or via SAML metadata). In that case &lt;SPAN style="color: #0000ff;"&gt;signing the request is not a security constraint&lt;/SPAN&gt;.&amp;nbsp; ...&lt;/P&gt;

&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If needed, please go ahead and log an enhancement request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 17:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/3435516#M517688</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-02-27T17:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/4461556#M569590</link>
      <description>&lt;P&gt;May we know is there any change/enhancement on this in latest ISE 3.0 or 3.1 ?&lt;/P&gt;
&lt;P&gt;We are doing ISE SAML integration and encounters the same problem.&lt;/P&gt;
&lt;P&gt;Thanks for the comments.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 08:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/4461556#M569590</guid>
      <dc:creator>kaiychen</dc:creator>
      <dc:date>2021-09-08T08:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: SAML AuthRequest assertions are not signed by the ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/4462071#M569607</link>
      <description>&lt;P&gt;There is still no configuration option for this in ISE 3.0/3.1 and I was not able to find any enhancement request filed related to this.&lt;/P&gt;
&lt;P&gt;The customer can use the &lt;A href="http://cs.co/ise-feedback" target="_blank" rel="noopener"&gt;Make a Wish&lt;/A&gt; feature to request this or you can reach out to the PM team internally via &lt;A href="https://cs.co/ise-pm" target="_blank" rel="noopener"&gt;cs.co/ise-pm&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 22:15:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/saml-authrequest-assertions-are-not-signed-by-the-ise/m-p/4462071#M569607</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2021-09-08T22:15:58Z</dc:date>
    </item>
  </channel>
</rss>

