Azure SAML authentication: validate identity provider certificate. (best pratices)

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Azure SAML authentication: validate identity provider certificate. (best pratices)

L3 Networker

Hi,

We have configured SAML on our portal and gateway.  By default Microsoft generates a self signed certificate that is valid for 3 years for every Enterprise application you create.

Is this secure enough to use the default self signed one and not validate it on my gateway/portal leave the check unmarked.

According to this article it should be save if you are running the correct version of Panos.

Securing your SAML Deployments - Knowledge Base - Palo Alto Networks

CVE-2020-2021 PAN-OS: Authentication Bypass in SAML Authentication (paloaltonetworks.com)

 

We could generate a certificate from our Internal PKI and upload this in Azure. 

What is the best pratice aroudn this.

 

3 REPLIES 3

Cyber Elite
Cyber Elite

Hi there.. I think with today's modern PANOS, this not going to be an issue. We routinely do SAML cert setups in our PS organization and the Validate Cert is always disabled. 

Hope this helps.

Help the community: Like helpful comments and mark solutions

L0 Member

Hi ZGomez, curious to know that did you checked the validate identity provider certificate. if so , then how did you get the identity provider certificate ?

AgilysysNetOps_0-1706784054201.png

 

Hi,

 

I ended up not checking the validity.  But on the Azure side you could generate, import your own certificate on the Application.

Or you can download it from there (the self signed).

On Entra-ID go to Enterprise applications search for you Global Protect Application, single sign-on , saml certificate here you could use your own or download the existing self signed. 

You will have to import his on palo alto.  

I believe it would be more safe to check the cert but also an overhead in administration.  The roll over happens every 3  years so you would also have te re-import it then on PANOS after roll over.

 

  • 1209 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!