IAM now requires logout responses to be signed before a new application can be added to the production IdP.
The saml_config in cdh.federated_auth.saml.settings.py requires an additional setting: logout_responses_signed=True. Currently, this is not included in the params of create_saml_config.
For a temporary fix, update the SAML_CONFIG object created with create_saml_config in the following way:
SAML_CONFIG['service']['sp']['logout_responses_signed'] = True
IAM now requires logout responses to be signed before a new application can be added to the production IdP.
The
saml_configincdh.federated_auth.saml.settings.pyrequires an additional setting:logout_responses_signed=True. Currently, this is not included in the params ofcreate_saml_config.For a temporary fix, update the
SAML_CONFIGobject created withcreate_saml_configin the following way: