NAM 4.4.4 IDP server SAML2 metadata and OAuth Key Enpiont list is not available while using ECC Signing and Encryption Certificates

  • 7023779
  • 19-Mar-2019
  • 19-Mar-2019

Environment


  • Access Manager 4.4.4

Situation

  • NetIQ Access Manager version 4.4.4 IDP server
  • ECC Certificates have been created and assigned to get used as Signing / Encryption Certificate for SAML2 and OAuth
  • The SAML2 and Liberty metadata URL is broken
  • The OAuth   https://idpa.kgast.nam.com:8443/nidp/oauth/nam/keys is returning an empty JSON

Resolution

  • These issues have been addressed to engineering
  • Note: with the current released NAM versions up to 4.4.4 and the upcoming NAM 4.5 release ECC Certificate will not be supported.

Additional Information

Please review as well the following TIDs