Identity Provider Certificate | Select the certificate that the IdP uses
to sign SAML messages that it sends to the firewall. You must select
an IdP certificate to ensure the integrity of messages that the
IdP sends to the firewall. To validate the IdP certificate against
the issuing Certificate Authority (CA), you must specify a Certificate
Profile in any authentication profile that references
the IdP server profile (see Device
> Authentication Profile). When generating or importing
a certificate and its associated private key, remember that the
key usage attributes specified in the certificate control what you
can use the key for. If the certificate explicitly lists key usage
attributes, one of the attributes must be Digital Signature, which
is not available in certificates that you generate on the firewall.
In this case, you must Import the
certificate and key from your enterprise certificate authority (CA)
or a third-party CA. If the certificate doesn’t specify key usage
attributes, you can use the key for any purpose, including signing
messages. In this case, you can use any method to obtain the certificate and key
for
signing SAML messages. IdP certificates support the following
algorithms: Public key algorithms—RSA (1,024 bits
or larger) and ECDSA (all sizes). A firewall in FIPS/CC mode supports
RSA (2,048 bits or larger) and ECDSA (all sizes). Signature algorithms— SHA1, SHA256, SHA384, and SHA512.
A firewall in FIPS/CC mode supports SHA256, SHA384, and SHA512.
|