Setup of security features
To improve security, you can set up the encryption of SAML assertions sent by Ping Identity and the signing of SAML requests sent by SonarQube.
Once you have Setup in Ping Identity, you can set up the following security features:
The encryption of SAML assertions emitted by the Ping Identity provider for SonarQube.
The signing of the SAML requests from SonarQube to the Ping Identity provider.
Setting up the encryption of SAML assertions
To enable the encryption of SAML assertions, you need to provide two things:
Service provider private key: PKCS8-stored private key used for signing the requests and decrypting responses from the identity provider.
Service provider certificate: X.509 certificate for the service provider used for signing the requests.
Follow the steps below.
Setting up the signing of SAML requests
You can set up the signing and verification of the SAML requests sent by SonarQube to the Ping Identity provider. To do so:
Set up the encryption of SAML assertions as explained above.
In SonarQube, do the following additional setting: In the SAML configuration, select the Sign requests option.
Related pages
Last updated
Was this helpful?