This process allows you to include Key Info with the XML message if you and your partner have agreed to this option.

Digital signing applies to service provider (SP)-initiated SSO under SAML 2.0, when specified by your partner agreement, and to either SLO profile using the POST or redirect bindings. Digital signing also applies if you are configuring an Attribute Query profile and have specified that you will sign attribute requests.

The step is not required for SAML 1.x IdP connections.

  1. On the Digital Signature Settings tab, select a signing certificate from the Signing Certificatelist.

    If you have not yet created or imported your certificate into PingFederate, click Manage Certificates. For more information, see Manage digital signing certificates and decryption keys.

  2. Optional: Select the Include the certificate in the signature <KeyInfo> element check box if you have agreed to send your public key with the message.

    Select the Include the raw key in the signature <KeyValue> element check box if your partner agreement requires it.

  3. Optional: Select the signing algorithm from the list.

    The default selection is RSA SHA256 or ECDSA SHA256, depending on the Key Algorithm value of the selected digital signing certificate. Make a different selection if you and your partner have agreed to use a stronger algorithm.