Enable SHA-256 for SAML requests to SSO
important
The instruction is only applicable to product version 10.1.6.1+ and package workfusion-full-package-10.1.6.1-851.tar.gz and newer.
The guide does not apply to the product deployed from the workfusion-full-package-10.1.6.1-279.tar.gz package.
By default, the encryption method for WorkSpace and Control Tower SAML requests is RSA SHA-1. Thus, in the SAML request body, in the SignatureMethod and DigestMethod parameters, you can see the #rsa-sha1 and sha1 values.
See the SAML request example with SHA-1 support
<?xml version="1.0" encoding="UTF-8"?>
<saml2p:AuthnRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://innovation-10-1-6-wfaw-10061-workfusion-lb1.workfusion.com:443/workfusion/saml/SSO" Destination="https://idp.workfusion.com/idp/profile/SAML2/POST/SSO" ForceAuthn="false" ID="a3ic9h3caf4j3ed75aahi9g3cf0a8ii" IsPassive="false" IssueInstant="2020-12-03T12:59:35.523Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">wf-sp-ct-innovation-10-1-6-wfaw-10061</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha1" />
<ds:Reference URI="#a3ic9h3caf4j3ed75aahi9g3cf0a8ii">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha1" />
<ds:DigestValue>OZDvC/g/PkY+tQuSFuNw9aB2bf2DalEB3cNZtJB87XU=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>ZhN3fjBNM6cL2/WzJwi78CYSHJH4MOzadmDutApOZbfN9gmtnUHWbdBIKByUlSGLGAhWN0HK01zJqjHz7R1XiXqDHgXa+U/P5e3NSCLGX2T0XZHW5xLC300+o5DiPJRRJBL4Jd+lFgxc0R/ZZLumDxw8VzSjJsU28rRq9CzzsOedy9KabNbChFj0dHsgIlw9QB88NnS8GIdKX3n6G+fXla0E4ODoh88qIh/CgK1z/tNy5rsG/ey6qCaUPulQS+fReyX86Upt4kRYL6vJcnuUow/+03HzFLjqx9waXF31BiuxOWBuR0zUeA/DFM9PeUjZrzMk/MwOiZObtW4cf1xH7g==</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIDOzCCAiOgAwIBAgIELKWnXjANBgkqhkiG9w0BAQsFADBOMQswCQYDVQQGEwJVUzELMAkGA1UE
CBMCV0YxCzAJBgNVBAcTAldGMQswCQYDVQQKEwJXRjELMAkGA1UECxMCV0YxCzAJBgNVBAMTAldG
MB4XDTIwMTIwMjEzNDIyMloXDTIxMDQwMTEzNDIyMlowTjELMAkGA1UEBhMCVVMxCzAJBgNVBAgT
AldGMQswCQYDVQQHEwJXRjELMAkGA1UEChMCV0YxCzAJBgNVBAsTAldGMQswCQYDVQQDEwJXRjCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJHMh165cG2aJkAy5fz3xlpVpTYR1StWqGXR
8LzbSkiDTL8ZxN3vElRf5X66tc2JvMc81N5wT7eEfgbllIQVTFwIEBkIzqGdwMy6mTAvmRNQLeg/
1Vr/eCb/rq1F53sHP/GGQ5yMnCt53UTN04akfpnGYCYiOdT19lYeusLnbtaiPXm5j5PZfV7d8+Cu
quPfdcgVKby0QD6VRUZQDOuAzuqQvPKrlvGW4p0I92HfGPMxFgk5ZkkQ0x6L8wi7iwNf92Ii2+Xx
BNM5e1YxnzFwUHCZUp1v7Uj9ltheOnIoud70ggUoqw3+6DbDPs5jpnAMuPnmlc+wo+6OEKQKUkeq
kq8CAwEAAaMhMB8wHQYDVR0OBBYEFB/Zk6twUJRq+X9cQDZ0hrgAk17AMA0GCSqGSIb3DQEBCwUA
A4IBAQANAuA2RW7Yuq3fwGwdv6dj9dVanTf7CdEPRyPTmsSpPCYSbtHRDV+sTLCorexeUDWVswZy
mqa8ZnsO1IXHYrDF5rcyT/8UIX7L3frdAsQfE/EO7VgcYIwn2rLMCpPgtE0T1+ZRqGnl7nmSuV+J
kiNYLUMKPTSytmRg3AlA4aShFnJWhtfWo/nx/hxiaAdBsZRMQWGJDXkDYgYH3gY5Pu8L5/3SnaRE
1YpRHUXdciI3HmRVr/x4l3q10lORPtLrn81oFMWIaqxWWCBDcHv7naA1DRb1jL4kyv4qj4jf98/V
V1Q9A4pMO69BGq3TQeKi/PzREVQiHGyhWR7hCM8HJT9S</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
</saml2p:AuthnRequest>
To change the default setting to RSA SHA-256, complete the following steps:
On the APP server, edit Control Tower properties file
<install_dir>/workfusion/conf/workfusion.propertiesas the application user (wfuser) and set the following properties as below:wf.sso.saml.signature.algorithm.uri=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256 wf.sso.saml.signature.digest.method.uri=http://www.w3.org/2001/04/xmlenc#sha256If the file contains no such properties, add them. If the environment is deployed in the High-Availability mode, repeat the step for the second APP server.
On the APP server, edit Workspace properties file
<install_dir>/workfusion/conf/workspace.propertiesas the application user (wfuser), and set the following properties as below:ws.sso.saml.signature.algorithm.uri=http://www.w3.org/2001/04/xmldsig-more#rsa-sha256 ws.sso.saml.signature.digest.method.uri=http://www.w3.org/2001/04/xmlenc#sha256If the file contains no such properties, add them. If the environment is deployed in the HA mode, repeat the step for the second APP server.
Restart Control Tower and WorkSpace:
wfmanager restart workfusion wfmanager restart workspaceFor the HA mode: restart the APP server where the required service is currently running. To see whether
workfusionorworkspaceservices are running on the server, execute the command:wfmanager status workfusion wfmanager status workspace
After you complete the above steps, Control Tower and WorkSpace send SAML requests with rsa-sha256 and sha256 values in the SignatureMethod and DigestMethod parameters.
See a SAML request example with SHA-256 support
<?xml version="1.0" encoding="UTF-8"?>
<saml2p:AuthnRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol" AssertionConsumerServiceURL="https://innovation-10-1-6-wfaw-10061-workfusion-lb1.workfusion.com:443/workfusion/saml/SSO" Destination="https://idp.workfusion.com/idp/profile/SAML2/POST/SSO" ForceAuthn="false" ID="a3ic9h3caf4j3ed75aahi9g3cf0a8ii" IsPassive="false" IssueInstant="2020-12-03T12:59:35.523Z" ProtocolBinding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Version="2.0">
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">wf-sp-ct-innovation-10-1-6-wfaw-10061</saml2:Issuer>
<ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:SignedInfo>
<ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
<ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
<ds:Reference URI="#a3ic9h3caf4j3ed75aahi9g3cf0a8ii">
<ds:Transforms>
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
</ds:Transforms>
<ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
<ds:DigestValue>OZDvC/g/PkY+tQuSFuNw9aB2bf2DalEB3cNZtJB87XU=</ds:DigestValue>
</ds:Reference>
</ds:SignedInfo>
<ds:SignatureValue>ZhN3fjBNM6cL2/WzJwi78CYSHJH4MOzadmDutApOZbfN9gmtnUHWbdBIKByUlSGLGAhWN0HK01zJqjHz7R1XiXqDHgXa+U/P5e3NSCLGX2T0XZHW5xLC300+o5DiPJRRJBL4Jd+lFgxc0R/ZZLumDxw8VzSjJsU28rRq9CzzsOedy9KabNbChFj0dHsgIlw9QB88NnS8GIdKX3n6G+fXla0E4ODoh88qIh/CgK1z/tNy5rsG/ey6qCaUPulQS+fReyX86Upt4kRYL6vJcnuUow/+03HzFLjqx9waXF31BiuxOWBuR0zUeA/DFM9PeUjZrzMk/MwOiZObtW4cf1xH7g==</ds:SignatureValue>
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>MIIDOzCCAiOgAwIBAgIELKWnXjANBgkqhkiG9w0BAQsFADBOMQswCQYDVQQGEwJVUzELMAkGA1UE
CBMCV0YxCzAJBgNVBAcTAldGMQswCQYDVQQKEwJXRjELMAkGA1UECxMCV0YxCzAJBgNVBAMTAldG
MB4XDTIwMTIwMjEzNDIyMloXDTIxMDQwMTEzNDIyMlowTjELMAkGA1UEBhMCVVMxCzAJBgNVBAgT
AldGMQswCQYDVQQHEwJXRjELMAkGA1UEChMCV0YxCzAJBgNVBAsTAldGMQswCQYDVQQDEwJXRjCC
ASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJHMh165cG2aJkAy5fz3xlpVpTYR1StWqGXR
8LzbSkiDTL8ZxN3vElRf5X66tc2JvMc81N5wT7eEfgbllIQVTFwIEBkIzqGdwMy6mTAvmRNQLeg/
1Vr/eCb/rq1F53sHP/GGQ5yMnCt53UTN04akfpnGYCYiOdT19lYeusLnbtaiPXm5j5PZfV7d8+Cu
quPfdcgVKby0QD6VRUZQDOuAzuqQvPKrlvGW4p0I92HfGPMxFgk5ZkkQ0x6L8wi7iwNf92Ii2+Xx
BNM5e1YxnzFwUHCZUp1v7Uj9ltheOnIoud70ggUoqw3+6DbDPs5jpnAMuPnmlc+wo+6OEKQKUkeq
kq8CAwEAAaMhMB8wHQYDVR0OBBYEFB/Zk6twUJRq+X9cQDZ0hrgAk17AMA0GCSqGSIb3DQEBCwUA
A4IBAQANAuA2RW7Yuq3fwGwdv6dj9dVanTf7CdEPRyPTmsSpPCYSbtHRDV+sTLCorexeUDWVswZy
mqa8ZnsO1IXHYrDF5rcyT/8UIX7L3frdAsQfE/EO7VgcYIwn2rLMCpPgtE0T1+ZRqGnl7nmSuV+J
kiNYLUMKPTSytmRg3AlA4aShFnJWhtfWo/nx/hxiaAdBsZRMQWGJDXkDYgYH3gY5Pu8L5/3SnaRE
1YpRHUXdciI3HmRVr/x4l3q10lORPtLrn81oFMWIaqxWWCBDcHv7naA1DRb1jL4kyv4qj4jf98/V
V1Q9A4pMO69BGq3TQeKi/PzREVQiHGyhWR7hCM8HJT9S</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</ds:Signature>
</saml2p:AuthnRequest>