Enable encrypted SAML responses between ETP and AD FS
To enable communication with encrypted SAML responses, configure both ETP and AD FS. This is an optional configuration.
- Configure ETP to send encrypted SAML responses.
- Configure AD FS for sending encrypted SAML responses.
Configure ETP to send encrypted SAML responses
Complete this procedure to configure ETP to send encrypted SAML responses.
Return to ETP and open the IdP you created for AD FS.
- In the Enterprise Center navigation menu, select .
- Click the name of the IdP you created for AD FS.
- Under Authentication Configuration settings, select Encrypted SAML Response.
- Click Save.
- Deploy the IdP configuration.
- If you are trying the new Enterprise Center interface, in the identity provider configuration, you can click the icon next to the Ready for Deployment status. A deployment icon also appears next to a failed deployment status in case you need to deploy the identity provider again. This action starts the deployment process.
- Deploy identity provider configuration changes in the list of Pending Changes. For more information, see Deploy configuration changes.
- Configure AD FS for sending encrypted SAML responses
Configure AD FS for sending encrypted SAML responses
Complete this procedure to configure AD FS for sending encrypted SAML responses.
- Return to the relying party trust. For example, IDP-RPT.
- In AD FS manager, edit properties of relying party trust.
- Under the Encryption tab, click Browse.
- Navigate to the certificate file cert.cer file.
- Click OK.