Hello,
our idp management team has some remarks on the way statuspage implements SAML for private pages:
- for signing : atlassian works with self signed certificates, that is not a good practice and not allowed on our idp
- Atlassian does not support encryption for communication between idp and statuspage.
Can i have feedback and potentially a road map on when this could be resolved?
thank you.
Hi Bram,
This is Jesse from the Statuspage support team. Thanks for the comments regarding the IdPs, signing, and encryption.
For signing, this isn't a feature we currently offer or have on our roadmap. I'd love to understand more of why self signing is insufficient. There's explicit trust since you're logging in to the manage portal and providing your certificate and that's the only certificate we trust.
For encryption, I am not sure I understand where we're not showing as encrypted. Can you help me understand what specifically isn't encrypted?
I also recommend opening a support ticket with us so we can look specifically into your use case and get additional information as needed. If you have a private page, you can reach out at support.atlassian.com. We can also open a feature request to implement this but would require more information. Thanks again!
Regards,
Jesse
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.