Note:
Contact support@whatfix.com to enable SAML Response Encryption.
To enable SAML Response Encryption, Whatfix Single Sign On (SSO) must be enabled. Contact support@whatfix.com to enable Whatfix SSO.
Overview of SAML Response Encryption
Provisions to enable SAML Response Encryption
Overview of SAML Response Encryption
Consider that you want to log in to your Whatfix dashboard using Whatfix Single Sign On (SSO). The login request goes from Whatfix to the Identity Provider (IdP) (IdP) to confirm your identity and facilitate login. Currently, the SSO response sent by the IdPs to Whatfix is sent as plain text. To improve the security of the information sent by the IdPs, Whatfix supports Security Assertion Markup Language (SAML) Response Encryption. With the SAML Response Encryption, Whatfix supports the provision for your IdPs to encrypt the SAML response provided by the IdPs.
Info:
The SAML response ensures that the request has come from Whatfix and enables you to log in to the Whatfix dashboard securely.
This response can then be decrypted by Whatfix using a private key. The SAML response encryption ensures that sensitive information in the response received from the IdP is protected during transmission.
Provisions to enable SAML Response Encryption
The following are the provisions supported for SAML Response Encryption:
Self Signed certificate
Customer provided certificate
Self Signed certificate
In this scenario, the SAML Response Encryption is done by your IDP using a public certificate generated by Whatfix. Whatfix shares the public certificate with your IdP in advance for the IdP to encrypt the response. After which, decryption at Whatfix’s end is done using a private key, which is also generated by Whatfix.
Customer provided certificate
In this scenario, you need to generate the public certificate to do the SAML Response Encryption. After which, decryption at Whatfix’s end is done using a private key also provided by you. You need to share both the public certificate and private key with Whatfix.