When configuring SAML, the SAML signing certificate is used to establish a trust relationship between the identity provider and the service provider to ensure that messages are coming from the expected identity and service providers. The SAML signing certificate is used to sign SAML requests, responses, and assertions from the Omnissa Access service to relying applications such as WebEx or Google Apps, or identity providers such as Microsoft Entra ID or Active Directory Federation Services (ADFS).
The SAML encryption certificate is used to encrypt and decrypt SAML assertions.
The Omnissa Access service automatically creates self-signed SAML signing and encryption certificates to handle the signing and encryption keys. You do not need a certificate from a certificate authority.
However, if your organization requires signing and encryption certificates from a certificate authority, you can generate a Certificate Signing Request (CSR) in the Omnissa Access console and send it to your certificate authority. When you receive the signed certificates, you upload them to the Omnissa Access service, replacing the self-signed certificates. When you do so, the Omnissa Access SAML metadata files are updated with the new certificates.
To access the SAML certificates and the Identity Provider (IdP) metadata and Service Provider (SP) metadata files:
- In the Omnissa Access console, select Resources > Web Apps > Settings.
- Select SAML Metadata in the Settings dialog box.
If you are configuring web apps, you will need the Identity Provider (IdP) metadata. If you are integrating with an identity provider, you will need the Service Provider (SP) metadata.
Was this page helpful?