Administer > System security > SAML Single Sign-On > SAML SSO setup > Configure SAML SSO using the standalone IdM > Task 14: Import the IdP public key into the IdM SAML keystore

Task 14: Import the IdP public key into the IdM SAML keystore

In this task, you will export the public key from the ADFS certificate and then import the key into the SAML keystore file of IdM. This task is required for IdM to decrypt SAML responses from ADFS.

Step 1. Export the public key portion of the ADFS federation service certificate

  1. From your operating system, start Active Directory Federation Services.
  2. Right-click Federation Service, and then click Properties.
  3. On the General tab, under Communicating certificate, click View.
  4. In the Certificate dialog box, select the Details tab.
  5. On the Details tab, click Copy to File.
  6. Click Next.
  7. On the Export Private Key page, make sure that No, do not export the private key is selected, and then click Next.
  8. On the Export File Format page, select DER encoded binary X.509 (.CER), and then click Next.
  9. On the File to Export page, specify the certificate file in File name, and then click Next.

    Note In this example, we use Per_ADFS.cer as the file name.

  10. Click Finish.

  11. Validate success by checking to see that the file you specified was created at the specified location.

Step 2. Import the ADFS public key into the IdM keystore

The IdM SAML keystore file is: <idm-service>\WEB-INF\classes\security\samlKeystore.jks.

To do this, run the following command:

keytool -importcert -alias some-alias -file Per_ADFS.cer -keystore samlKeystore.jks

Note When prompted for the password of samlKeystore.jks, enter nalle123.

If you want to use your own keystore file instead of the out-of-box one, you need to do the following:

  1. Replace the out-of-box keystore file with your own one.
  2. If your keystore file uses a different name, specify your file in the <idm-service>\WEB-INF\spring\applicationContext.properties file:

    idm.saml.keystore=classpath:security/samlKeystore.jks

    Replace samlKeystore.jks with your own file name.

  3. Specify the following parameters accordingly in the <idm-service>\WEB-INF\spring\applicationContext.properties file:

    • idm.saml.keystore.password=ENC(xxx)
    • idm.saml.keystore.defaultKey.name=ENC(xxx)
    • idm.saml.keystore.defaultKey.password=ENC(xxx)

    Note Replace the ENC(xxx) parts with your own values.