cloudstack/plugins/user-authenticators
Abhishek Kumar f0faa4a6b3 saml: signature check improvements
Adminstrators should ensure that IDP configuration has a signing certificate for the actual signature check to be performed. In addition to this, this change introduces a new global setting saml2.check.signature, with the default value of true, which can deliberately fail a SAML login attempt when the SAML response has a missing signature.
Purges the SAML token upon handling the first SAML response.

Authored-by: Rohit Yadav <rohit.yadav@shapeblue.com>

Signed-off-by: Abhishek Kumar <abhishek.mrt22@gmail.com>
2024-07-15 17:35:07 +05:30
..
ldap Updating pom.xml version numbers for release 4.18.2.1 2024-07-04 16:16:56 +05:30
md5 Updating pom.xml version numbers for release 4.18.2.1 2024-07-04 16:16:56 +05:30
pbkdf2 Updating pom.xml version numbers for release 4.18.2.1 2024-07-04 16:16:56 +05:30
plain-text Updating pom.xml version numbers for release 4.18.2.1 2024-07-04 16:16:56 +05:30
saml2 saml: signature check improvements 2024-07-15 17:35:07 +05:30
sha256salted Updating pom.xml version numbers for release 4.18.2.1 2024-07-04 16:16:56 +05:30