gpt4 book ai didi

azure - Azure AD 中的 SAML2 token 签名

转载 作者:行者123 更新时间:2023-12-03 00:14:08 24 4
gpt4 key购买 nike

为了设置一些上下文,我们使用 Azure AD SAML2 support使用 Office365 凭据登录我们的网站。

阅读元数据文档后,我有两个问题:

This document状态:

A federation metadata document published by Azure AD can have multiple signing keys , such as when Azure AD is preparing to update the signing certificate. When a federation metadata document includes more than one certificate, a service that is validating the tokens should support all certificates in the document.

这是否意味着必须对照所有列出的证书检查 SAML2 身份验证 token 响应签名,如果其中任何一个证书匹配,则视为有效?

This document状态:

This topic discusses what you need to know about the public keys that are used in Azure AD to sign security tokens. It is important to note that these keys rollover on a 6 week schedule. In an emergency, a key could be changed much sooner than 6 weeks. All applications that use Azure AD should be able to programmatically handle the key rollover process.

这个 6 周更新计划是否涉及 SAML2 token 签名?如果是这样,为什么元数据中列出的证书有效期更长?

最佳答案

没有必要针对所有 key 验证签名,但如果您这样做并且签名验证,那么它应该被视为有效。

您可以使用 ds:Signature 中的 ds:KeyInfo 来确定要使用的 key 。

关于azure - Azure AD 中的 SAML2 token 签名,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/33609868/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com