SurePassID Identity Provider

Release 2026.4

Overview

This release introduces significant security enhancements, policy evaluation improvements, and expanded protocol support across all three federation surfaces of the SurePassID Identity Provider: SAML 2.0, OpenID Connect (OIDC), and the Microsoft Entra ID External Authentication Method (EAM). Key improvements include centralized policy evaluation, enhanced security validation, comprehensive Single Logout (SLO) support for both SAML and OIDC, a full OIDC authorization server implementation, EAM support for Entra ID multifactor authentication, and improved audit logging.

All tenant, client, and protocol configuration is performed in the SurePassID Admin Portal.


✨ New Features

1. Centralized Federation Policy Evaluation

Key Benefits:

  • ✅ Consistent policy evaluation across all SSO applications
  • ✅ Centralized policy logic in shared library
  • ✅ Enhanced audit logging with JSON-serialized results
  • ✅ Support for IP whitelist and time-based access controls
  • ✅ Multiple enforcement modes (Ignore, Log, Enforce)

2. Enhanced SSO Security Validation Audit Logging

2.1 Replay Attack

  • Audit Code: AuditResultCode.SSOReplayAttackDetected

2.2 SP Issuer Validation

2.3 AuthnRequest Signature Validation

  • Audit Codes:
    • AuditResultCode.SSOAuthnRequestSignatureInvalid
    • AuditResultCode.SSOAuthnRequestSignatureRequired
    • Include telemetric data for further automated analysis

3. Comprehensive Single Logout (SLO) Support

3.1 SP-Initiated Logout

  • Support: Full support for Service Provider initiated logout requests
  • Features:
    • Validates logout request signatures (if configured)
    • Checks for replay attacks on logout requests
    • Validates destination URL matches IdP SLO endpoint
    • Sends signed logout responses (configurable)
    • Removes SAML sessions from cache

3.2 IdP-Initiated Logout

  • Support: Full Identity Provider initiated logout with response handling
  • Features:
    • Processes logout responses from Service Providers
    • Logs success/failure status codes
    • Handles status messages and error conditions

3.3 Logout Request Security Validations

Replay Attack Prevention:

  • Audit Code: AuditResultCode.SSOReplayAttackDetected

Destination Validation:

  • Audit Code: AuditResultCode.SSOLogoutDestinationMismatch

Signature Validation:

  • Audit Codes:
    • AuditResultCode.SSOLogoutSignatureRequired
    • AuditResultCode.SSOLogoutSignatureInvalid
  • Protection: Validates request authenticity and integrity

4. SAML Session Management

Location: SamlRequestIdCache (referenced in SLO service)

Features:

  • Session tracking with SessionIndex support
  • Session cache for logout request validation
  • Automatic session removal on logout
  • Session information includes:
    • User ID
    • Partner ID
    • SP Entity ID
    • Creation timestamp

5. Enhanced Audit Trail

Improvements:

  • Detailed audit logging for all SSO/SLO operations
  • JSON-serialized policy evaluation results
  • Security event tracking with severity levels
  • Request/response correlation via unique IDs

New Audit Result Codes: | Code | Description | |------|-------------| | SSOReplayAttackDetected | Duplicate request ID detected | | SSOAuthnRequestSignatureInvalid | AuthnRequest signature failed verification | | SSOAuthnRequestSignatureRequired | Signature required but not present | | SSOLogoutDestinationMismatch | Logout destination doesn't match expected URL | | SSOLogoutSignatureRequired | Logout signature required but not present | | SSOLogoutSignatureInvalid | Logout signature failed verification | | SSOAcsUrlMismatch | ACS URL doesn't match registered URL |

6. OpenID Connect (OIDC) Provider

The Identity Provider now exposes a full OpenID Connect authorization server alongside SAML 2.0. Each tenant has its own issuer, signing keys, and discovery document.

Endpoints: | Purpose | URL Pattern | |---------|-------------| | Discovery | /oidc/{domain}/.well-known/openid-configuration | | JWKS | /oidc/{domain}/jwks | | Authorization | /oidc/{domain}/authorize | | Token | /oidc/{domain}/token | | UserInfo | /oidc/{domain}/userinfo | | Logout | /oidc/{domain}/logout |

Supported Capabilities:

  • ✅ Authorization Code flow (response_type=code)
  • ✅ Refresh token grant with rotation and reuse detection
  • ✅ PKCE (S256), enforceable per client
  • ✅ Client authentication via client_secret_basic, client_secret_post, and none (public clients)
  • ✅ Signed request objects (JAR, RFC 9101) using RS256
  • ✅ Claims parameter support (OIDC Core section 5.5)
  • ✅ UserInfo endpoint with scope-based claim release
  • ✅ Consent screen with durable per-client consent grants
  • ✅ RP-initiated logout with front-channel and back-channel Single Logout
  • ✅ JWKS publication with two-key overlap for zero-downtime key rotation
  • ✅ Per-tenant and per-IP rate limiting on OIDC endpoints

Refresh Token Security: Refresh tokens are rotated on every use. Presenting a previously rotated token is treated as replay and revokes the entire token chain. An absolute session lifetime is enforced independently of rotation.

Not supported in this release: client_credentials grant, private_key_jwt client authentication, implicit and hybrid flows, Pushed Authorization Requests (PAR), DPoP, and JARM.

7. Microsoft Entra ID External Authentication Method (EAM)

The Identity Provider can now act as an external authentication method for Microsoft Entra ID, allowing SurePassID MFA to satisfy an Entra ID multifactor authentication requirement.

Endpoints: | Purpose | URL Pattern | |---------|-------------| | Discovery | /eam/{domain}/.well-known/openid-configuration | | JWKS | /eam/{domain}/jwks | | Authorization | /eam/{domain}/authorize |

Supported Capabilities:

  • ✅ Signed request object (JAR) validation against the Entra ID JWKS
  • ✅ Parameter mode using id_token_hint for deployments that do not send a request object
  • ✅ acr and amr claims reporting the authentication methods actually used
  • ✅ RS256-signed id_token returned by form_post after successful MFA
  • ✅ Replay protection rejecting a reused request object jti
  • ✅ Per-tenant EAM configuration including client ID, redirect URIs, and ACR override
  • ✅ Full audit coverage of discovery, authorization, and callback paths

Note: EAM replay protection shares the SAML request ID cache, so SamlCache.RequestIdExpirationMinutes also governs the EAM replay window.

New Audit Result Codes (OIDC and EAM): | Code | Description | |------|-------------| | SSOReplayAttackDetected | Reused EAM request object jti detected | | ApiAccessViolation | EAM or OIDC request failed parameter validation |


🔄

6. OIDC Client Configuration

Each OIDC relying party is registered per tenant with the following settings:

Setting Description
Client ID Public identifier for the relying party
Client Secret Stored as a hash; omit for public clients
Redirect URIs Exact-match list of permitted redirect targets
Scopes Scopes the client is permitted to request
Grant Types authorization_code and optionally refresh_token
Require PKCE Enforces S256 code challenge for this client
Require Consent Forces the consent screen even for previously granted scopes
Request Object JWKS URI Key source for validating signed request objects (JAR)
ACR Override Overrides the advertised authentication context value

7. EAM Tenant Configuration

Setting Description
Client ID Entra ID application client identifier
Entra OpenID Config URL Discovery document used to retrieve the Entra ID signing keys
Redirect URIs Permitted form_post return targets
ACR Override Overrides the acr value asserted after successful MFA
Client Secret Optional additional defense-in-depth check

Tenants may also be configured through Eam.{domain}.* keys in web.config, which remain supported for existing deployments.


🔒 Security Enhancements

1. Extended Logging

2. Certificate Management

Enhanced certificate retrieval with support for multiple key management providers:

  • None (plaintext)
  • SurePassLocal (local encryption)
  • SurePass (remote KMS)
  • SafeNet, FutureEx, nCipher, Townsend, Kms (HSM providers)

3. OIDC Token Security (new)

  • Refresh token rotation: A refresh token is invalidated as soon as it is exchanged, and a new one is issued
  • Reuse detection: Presenting an already-rotated refresh token revokes the entire descendant token chain
  • Absolute session lifetime: Enforced independently of rotation, capping how long a session can be extended
  • Single-use authorization codes: Codes are bound to the issuing client and PKCE challenge, and cannot be redeemed twice
  • Access token revocation: Revoked access tokens are tracked in a deny-list and rejected at the UserInfo endpoint
  • Exact-match redirect URI validation: Redirect targets must match a registered URI exactly

4 OIDC Endpoint Rate Limiting (new)

OIDC endpoints are rate limited per tenant and per calling IP address to reduce the impact of credential stuffing and enumeration attempts.

8. EAM Request Validation (new)

  • Request objects are validated against the Entra ID JWKS before any authentication is performed
  • Replay protection rejects a reused request object jti
  • Parameter mode validates the supplied id_token_hint was issued by Entra ID
  • The asserted subject must match the expected login_hint or sub, and the request is rejected if neither is present

9. Signing Key Rotation (new)

Both OIDC and EAM publish JWKS documents that support a two-key overlap window, allowing signing keys to be rotated without invalidating tokens that are still in flight.


🧭 Deployment Sizing and Compatibility

Deployment Cache Provider Session Expiration Cleanup Frequency
Small (< 100 users) InMemory 8 hours Automatic
Medium (100-1000 users) SqlServer 8 hours Every 5 minutes
Large (> 1000 users) SqlServer 4 hours Every 2 minutes

In-memory cache: Sub-millisecond lookups, automatic cleanup every 60 seconds, memory grows with active sessions, and state is lost on application restart.

SQL Server cache: Typical lookup of 2-5 ms, persists across restarts, configurable batch cleanup, and suitable for thousands of concurrent sessions.

Note: These settings apply to the SAML request ID and session caches. The OIDC session cache is in-memory only and is not affected by the cache provider selection.

Tested Service Providers

Salesforce, Microsoft 365 / Entra ID, Google Workspace, AWS IAM Identity Center, ServiceNow, Okta (as SP), and custom SAML 2.0 Service Providers.

Browser Support

Chrome, Firefox, Safari, and Microsoft Edge (current versions). Internet Explorer 11 has limited Single Logout support.

Framework Requirements

  • .NET Framework 4.8
  • SQL Server 2016 or later (required for the SqlServer cache provider)
  • IIS 10 or later recommended

⚠️ Known Issues

1. HTTP-Redirect Binding for Logout Responses

Issue: Logout responses default to HTTP-POST even when HTTP-Redirect is configured
Reason: HTTP-Redirect requires query string signature which is more complex
Workaround: Use HTTP-POST binding for logout (recommended)
Status: Under consideration for future release

2. Session Index Cleanup

Issue: In-memory session cache may grow if SPs don't send logout requests
Impact: Minimal - sessions auto-expire based on timestamp
Workaround: Sessions automatically expire, or restart service to clear
Status: Monitoring for future optimization

3. OIDC Session Cache Is Not Shared Across Nodes

Issue: The OIDC session cache is in-memory only and is not affected by the SamlCache.Provider setting
Impact: In a load-balanced deployment without sticky sessions, an OIDC logout handled by a different node than the one that registered the relying party may not notify every participant
Workaround: Enable sticky sessions for OIDC logout traffic
Status: A shared OIDC session store is under consideration for a future release

4. OIDC Protocol Features Not Yet Implemented

Issue: The following OpenID Connect features are not supported in this release: client_credentials grant, private_key_jwt client authentication, implicit and hybrid flows, Pushed Authorization Requests (PAR), DPoP, and JARM
Impact: Relying parties requiring these features cannot be onboarded
Workaround: Use the Authorization Code flow with PKCE, which is the recommended pattern for both confidential and public clients
Status: PAR, DPoP, and JARM have design documents and are candidates for a future release

5. EAM Replay Window Is Shared With SAML

Issue: EAM request object jti replay protection uses the SAML request ID cache, so SamlCache.RequestIdExpirationMinutes (default 5) also sets the EAM replay window
Impact: If an Entra ID request object remains valid longer than the configured window, its cache entry can expire before the request object does
Workaround: Ensure the configured expiration is at least as long as the Entra ID request object lifetime
Status: A dedicated EAM replay window is under consideration


🚨 Deprecation Notices

None in This Release

All existing APIs remain supported. No deprecation warnings.


⬆️ Upgrade Notes

Prerequisites

  • .NET Framework: 4.8 or higher
  • Database: SQL Server 2016 or higher
  • ComponentSpace SAML: 2.0 or higher

Deployment Steps

  1. Backup: Create full backup of database and application
  2. Update Binaries: Deploy new SurePassIdp assemblies
  3. Update Shared Library: Deploy updated SurePassClassLib.dll
  4. Test SSO: Verify existing SSO integrations still work
  5. Configure SLO: Enable Single Logout for SP applications
  6. Test SLO: Verify logout operations work correctly
  7. Review Logs: Check diagnostic traces and audit logs

Rollback Plan

If issues occur:

  1. Restore previous application binaries
  2. No database rollback needed (schema unchanged)
  3. Clear application cache
  4. Restart application pool

🛠 Support and Troubleshooting

Diagnostic Tracing

Enable detailed diagnostic tracing to troubleshoot issues:

<appSettings>
    <add key="Server.TracePath" value="C:\Logs\SurePassIdp\" />
    <add key="Trace.Enabled" value="true" />
</appSettings>

Trace files are created daily with naming: SurePassIdp<YYYYMMDD>.log

Common Issues

Issue: Replay Attack Detected

Symptom: SSOReplayAttackDetected audit event
Cause: SP is reusing request IDs or user is refreshing page
Solution: Configure SP to generate unique request IDs; educate users not to refresh during auth

Issue: Signature Verification Failed

Symptom: SSOAuthnRequestSignatureInvalid audit event
Cause: Certificate mismatch, clock skew, or tampered request
Solution: Verify SP certificate matches, check system clocks, review network security

Issue: Logout Destination Mismatch

Symptom: SSOLogoutDestinationMismatch audit event
Cause: SP sending logout request to wrong URL
Solution: Configure SP with correct IdP SLO endpoint URL

Audit Log Queries

Find recent security events:

SELECT TOP 100 *
FROM PartnerUserAudit
WHERE ResultCode IN (9139, 9140, 9141, 9142, 9143, 9144, 9145)
ORDER BY AuditDate DESC

Find policy violations:

SELECT TOP 100 *
FROM PartnerUserAudit
WHERE ResultCode IN (9069, 9070, 9061, 9065)
ORDER BY AuditDate DESC

📧 Contact

For questions, issues, or feature requests:

  • Support: Contact SurePassID Support

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com