Blog
Announcement: SAML Encryption for Legacy Authentication in Lifecycle and Portals
Author
mwoodberry
SailPoint
Problem
Some security compliance regimes require that all assertions handled in some way by a 3rd party be encrypted. Currently, there is not a configuration that allows customers to require or implement SAML encryption standards for authentication into the Non-Employee Risk Management Lifecycle dashboard or a Non-Employee Risk Management Portal.
Solution
As continuous improvement to NERM’s security posture and to ensure adherence to FIPS-validated cryptographic standards, Non-Employee Risk Management has introduced a new ‘Encrypt SAML Assertions’ toggle in Single Sign-On settings for both Lifecycle and Portals.
- When ‘Encrypt SAML Assertions’ is ON, ‘SSO Only’ is set to ON and cannot be changed.
- A clickable link for SAML metadata endpoint is provided.
- The ‘Certificates’ table will contain up to two certificates, and an option to download the metadata XML file is available for each certificate.
For tenants using ISC authentication, ISC will handle decrypting the SAML assertion, so there is no need to configure encrypted SAML authentication in Lifecycle.
Tenants using ISC authentication can enable SAML authentication for their Portals since Portals can use different Identity Providers.
Who is affected?
This option will be available to all Non-Employee Risk Management customers. The Encrypted SAML assertion options will not be relevant for customers with Non-Employee Risk Management Lifecycle authentication configured through Identity Security Cloud, although these customers may use encrypted SAML assertions for Portals.
Action Required
Customers that want to take advantage of this security enhancement should enable the new ‘Encrypt SAML Assertions’ setting. Customers will need to ensure they add the corresponding keys to their IDP before enabling and saving the setting in the NERM UI.
Important Dates
- September 27, 2024 - Begin customer Sandbox tenant enablement
- October 7, 2024 - Begin customer Production tenant enablement