SAML Request signing keys / certificates

SAML Request signing keys / certificates

See also: SAML Response certificates

The SAML Requests are signed by the service provider (SP). Kantega SSO acts as the SP in SAML and integrates with the identity provider. You update SAML request certificates from Kantega SSO in Identity Providers > Key Management and click “Add standby key”.

image-20260728-140859.png

After this you can click “download” on the link under the standby key, and the certificate file will we downloaded to your computer. The certificate here needs to be installed in the Identity Provider afterward so that the identity provider can verify the certificates. After properly installed at the identity provider, you may promote the standby key to be the new key used for signing SAML requests.

image-20260728-140939.png

 

The ability to change the encryption algorithm and key size was added in version 6.37.2 and 7.37.2. Currently supports “RSA_2048” and “RSA_4096”, but in the future more options might be added.

 

Upload guides for specific identity providers:

Configure SAML Request Signature Verification in Okta:

Update Kantega SSO SAML signing certificate in Okta

Configure SAML Request Signature Verification in Microsoft Entra Id:

https://learn.microsoft.com/en-us/entra/identity/enterprise-apps/howto-enforce-signed-saml-authentication