Use the following hints to adjust settings on the Assertion Content tab page.
Signing and Encryption
- Request/Response Signing
-
Specifies what parts of messages the identity provider requires the service provider to sign digitally.
- Encryption
-
When selected, the service provider must encrypt NameID elements.
- Certificate Aliases
-
Specifies aliases for certificates in the OpenAM key store that are used to handle digital signatures, and to handle encrypted messages.
Specify a Key Pass if the private key password is different from the key store password, which is stored encrypted in the
.keypassfile for the server. For instructions on working with key pairs, also see To Change the Signing Key for Federation.
NameID Format
- NameID Format List
-
Specifies the supported name identifiers for users that are shared between providers for single sign on. If no name identifier is specified when initiating single sign on, then the identity provider uses the first one in the list.
- NameID Value List
-
Maps name identifier formats to user profile attributes. The
persistentandtransientname identifiers need not be mapped.
Authentication Context
- Mapper
-
Specifies a class that implements the
IDPAuthnContextMapperinterface and sets up the authentication context. - Default Authentication Context
-
Specifies the authentication context used if no authentication context specified in the request.
- Supported Contexts
-
Specifies the supported authentication contexts, where the Key and Value can specify a corresponding OpenAM authentication method, and the Level corresponds to an authentication module authentication level.
Assertion Time
- Not-Before Time Skew
-
Grace period in seconds for the
NotBeforetime in assertions. - Effective Time
-
Validity in seconds of an assertion.

