|
1 | 1 | # If 'strict' is True, then the Java Toolkit will reject unsigned |
2 | 2 | # or unencrypted messages if it expects them signed or encrypted |
3 | 3 | # Also will reject the messages if not strictly follow the SAML |
4 | | -onelogin.saml2.strict = false |
| 4 | +onelogin.saml2.strict = true |
5 | 5 |
|
6 | 6 | # Enable debug mode (to print errors) |
7 | 7 | onelogin.saml2.debug = false |
@@ -50,33 +50,32 @@ onelogin.saml2.sp.privatekey = |
50 | 50 | # |
51 | 51 |
|
52 | 52 | # Identifier of the IdP entity (must be a URI) |
53 | | -onelogin.saml2.idp.entityid = https://app.onelogin.com/saml/metadata/672234 |
| 53 | +onelogin.saml2.idp.entityid = |
54 | 54 |
|
55 | 55 | # SSO endpoint info of the IdP. (Authentication Request protocol) |
56 | 56 | # URL Target of the IdP where the SP will send the Authentication Request Message |
57 | | -onelogin.saml2.idp.single_sign_on_service.url = https://sgarcia-us-preprod.onelogin.com/trust/saml2/http-post/sso/672234 |
58 | | - |
| 57 | +onelogin.saml2.idp.single_sign_on_service.url = |
59 | 58 | # SAML protocol binding to be used when returning the <Response> |
60 | 59 | # message. Onelogin Toolkit supports for this endpoint the |
61 | 60 | # HTTP-Redirect binding only |
62 | 61 | onelogin.saml2.idp.single_sign_on_service.binding = urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect |
63 | 62 |
|
64 | 63 | # SLO endpoint info of the IdP. |
65 | 64 | # URL Location of the IdP where the SP will send the SLO Request |
66 | | -onelogin.saml2.idp.single_logout_service.url = https://sgarcia-us-preprod.onelogin.com/trust/saml2/http-redirect/slo/672234 |
| 65 | +onelogin.saml2.idp.single_logout_service.url = |
67 | 66 |
|
68 | 67 | # Optional SLO Response endpoint info of the IdP. |
69 | 68 | # URL Location of the IdP where the SP will send the SLO Response. If left blank, same URL as onelogin.saml2.idp.single_logout_service.url will be used. |
70 | 69 | # Some IdPs use a separate URL for sending a logout request and response, use this property to set the separate response url |
71 | | -onelogin.saml2.idp.single_logout_service.response.url = https://sgarcia-us-preprod.onelogin.com/trust/saml2/http-redirect/slo/672234 |
| 70 | +onelogin.saml2.idp.single_logout_service.response.url = |
72 | 71 |
|
73 | 72 | # SAML protocol binding to be used when returning the <Response> |
74 | 73 | # message. Onelogin Toolkit supports for this endpoint the |
75 | 74 | # HTTP-Redirect binding only |
76 | 75 | onelogin.saml2.idp.single_logout_service.binding = urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect |
77 | 76 |
|
78 | 77 | # Public x509 certificate of the IdP |
79 | | -onelogin.saml2.idp.x509cert = -----BEGIN CERTIFICATE-----MIIGZTCCBE2gAwIBAgIULEW2UPHc+tQMo/j0NBM+8SbWK7IwDQYJKoZIhvcNAQELBQAwcjELMAkGA1UEBhMCVVMxKzApBgNVBAoMIk9uZUxvZ2luIFRlc3QgKHNnYXJjaWEtdXMtcHJlcHJvZCkxFTATBgNVBAsMDE9uZUxvZ2luIElkUDEfMB0GA1UEAwwWT25lTG9naW4gQWNjb3VudCA4OTE0NjAeFw0xNzA2MjAxMDA4MTlaFw0yMjA2MjExMDA4MTlaMHIxCzAJBgNVBAYTAlVTMSswKQYDVQQKDCJPbmVMb2dpbiBUZXN0IChzZ2FyY2lhLXVzLXByZXByb2QpMRUwEwYDVQQLDAxPbmVMb2dpbiBJZFAxHzAdBgNVBAMMFk9uZUxvZ2luIEFjY291bnQgODkxNDYwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDzOWemVjGJTRG72AlAYnNapp26qnnNeNQVt4e56xi+56hjW5OTfgriP27rvAOd+CePIYA3ZyL0pk2LOPA/JtA0JA8LKN1vcGvfJcrpcsbFM5Y2BN5wTnqprT8rvG5eFmeK4r72qJ4wb4bUZJroT9+fU/gs/JOizhP4Z79icLQcbTTe0mc4n+/yoTxThAAraAsiOr3KQzXlTYB8zPMA2GI9TJ5Djc+g52C2vk2OhLEaSAPXGKLhvWukbyUMS34ofnqHaNO0ZbwUmw+8lgHBjIndXsSaFsm18SPnKTtfs1cLekzDveFvJ0T5V8PQWooqWUdg3hkrIiKZpOIcz8uYElpkQDJ2q++MjC7VsT1tKkjMGTv7SMicPscxAG89OaWRg+zmaDzqvdtNPGFe+8oatXp0FBMsnlsyIwdcoHTstloVEcOTSiT8wmjvkkIg5YR6vScmLhR6AQArRP2lWR0kXoSddEDk5fFDG+qMLus+N09YfUOKPswP6MtT9vNhPeIBP87qZLl4qbVCY+TWdNr5lONAH+Xmtk3Pf2phg74qZIZ87bEmJBSXKp8/Qm6Y4ruj6S+SPYt3/vKw130VfaGaSFyOlfAq3naiJqffa2tzneJ7Om/sHFee2Zj2hYqncxu6KR1qeR7lucB5o7z0ljGeUukp8GiVcubsQ3RNnfuCdsaeSwIDAQABo4HyMIHvMAwGA1UdEwEB/wQCMAAwHQYDVR0OBBYEFKewY7diVRP96TRYhW2f/1ktWrJAMIGvBgNVHSMEgacwgaSAFKewY7diVRP96TRYhW2f/1ktWrJAoXakdDByMQswCQYDVQQGEwJVUzErMCkGA1UECgwiT25lTG9naW4gVGVzdCAoc2dhcmNpYS11cy1wcmVwcm9kKTEVMBMGA1UECwwMT25lTG9naW4gSWRQMR8wHQYDVQQDDBZPbmVMb2dpbiBBY2NvdW50IDg5MTQ2ghQsRbZQ8dz61Ayj+PQ0Ez7xJtYrsjAOBgNVHQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQELBQADggIBAC2TQ4yqwk0ePey99JYI5PfMRVEnUyyCSPfKmyVJgoOZwk97+CZuq1MNqGavcExd1ofc4wkN3unk/g7qVRPBV24k9FZaicYrp5maSHakL2SJD8qo/deohYFaeH8RzszxEZbJJYMLiXyRJi44T28TyF8admIwUJVg/KBhNAHi/IlAsRWPL92nWJjSCBHgiPaG5HF10t/GaQSJuQpdhxniUlseuqXZ/Qm0MjAgSTlyaBIxLyOErrpVujwiR5RTHLw0wn+2P0WmfVp7e79GOqzFuwmoLfxUtJgalc7av9VwFdEB2nWF2hu7BwE9rzg8FTaw1uAEu+LQ++IUuI+ydparFWoo/IwtSrXF59mBoKMld58K4L+TfWwUYF3hAmH2XNiSBTFZn1HBsK+XqS1CUGD8R0WSVvQC2jjFbxztFkrOIzz5ITLzKcjr1E86r5PvBQXeeTvVz6g2L+wEA5VXGYh/RItHEkuwn7EPWpvJUfc5B0m57rfr0+UqWZaLbhczrmHFn0HaDXcs2ldi7y+Eiv6IP3vrJrHhdCDlVPLQH8w0f4vNcR8YYVOfWFHYzyo4oqRYFMRmoqfubs90zGLcB5ugm56k5VaseP+VGwjjTEyiD4CYPLEvKm0Z2M0L6MIkhp/9VYl8ZAWvPGKFMSaANkiMlux2uEBeG3s4nLQcunumphAo-----END CERTIFICATE----- |
| 78 | +onelogin.saml2.idp.x509cert = |
80 | 79 |
|
81 | 80 | # Instead of use the whole x509cert you can use a fingerprint |
82 | 81 | # (openssl x509 -noout -fingerprint -in "idp.crt" to generate it, |
|
0 commit comments