Holder-of-key (Section)#

Path: /profiles/profile{id, type}/settings/saml-idp-service/assertion/holder-of-key

Configure Holder-of-Key settings for the assertions.

Parameters#

NameTypeRequiredDefaultDescription
require-certificate-bindingbooleanoptionalfalseSet this to true to always include a Holder Of Key subject confirmation when issuing an assertion. When this setting is enabled and no certificate was available, an error will be returned. When disabled, a Holder of Key subject confirmation will be included when a certificate is available.
x509-certificate-attribute-namenon-empty-stringoptionalx509_client_certificateThe name of the subject attribute that contains the X.509 certificate to be used for Holder Of Key subject confirmations. Defaults to ‘x509_client_certificate’.
include-certificatebooleanoptionaltrueSet this to true to include the X.509 certificate in the Holder Of Key subject confirmation. Defaults to true.
include-subject-key-identifierbooleanoptionaltrueSet this to true to include the Subject Key Identifier in the Holder Of Key subject confirmation. If no Subject Key Identifier extension was included in the certificate, this setting will be ignored. Defaults to true.
include-subject-namebooleanoptionaltrueSet this to true to include the Subject Name in the Holder Of Key subject confirmation. Defaults to true.
include-subject-issuer-serialbooleanoptionaltrueSet this to true to include the Subject Issuer and Serial Number in the Holder Of Key subject confirmation. Defaults to true.

Was this helpful?