Plugin for IdentityServer4 that enables IdentityServer to function as a Ws-Federation Identity Provider.
The easiest way to get started is to:
- Clone the IdentityServer4.Quickstart project of your choice (unless you plan to build the UI from scratch)
- Install the
package. - Configure Startup.cs as below
Also, see the Samples folders for a working server (src/SampleServer) and client (src/SampleClient).
Do the following in Startup.cs
to use this plugin with Core.
If you don't use MVC, obviously take that out.
public void ConfigureServices(IServiceCollection services)
// If you don't manually specify the digest and signature algorithms, it'll fail.
var certificate = new X509Certificate2("IdentityServer4.WsFederation.Testing.pfx", "pw");
var signingCredentials = new SigningCredentials(new X509SecurityKey(certificate), SecurityAlgorithms.RsaSha256Signature, SecurityAlgorithms.Sha256Digest);
var builder = services.AddIdentityServer(options =>
options.IssuerUri = "urn:idsrv4:wsfed:server:sample";
.AddSigningCredential(signingCredentials) // Must use this overload.
.AddInMemoryApiResources(new List<ApiResource>())
public void Configure(IApplicationBuilder app, IHostingEnvironment env)
// app.UseMvc.....
Right now, this library is in alpha. Consequently, only a subset of the WsFederation standard is supported. It's also likely that some features of IdentityServer aren't well integrated yet.
- Signin
- Metadata
- Signout
- wa
- wreply
- wctx
- wfresh
- wa
- wresult
- wctx
I plan to do this stuff.
These things are pretty much goals for the mid-term.
- Supporting the rest of the request parameters
- Better input validation.
- Events.
These will mostly correspond to the parts of WsFederation that were not mentioned above.
- Rst as an input parameter.
- Pointers to the incoming rst or outgoing rstr.
- Encryption?
- Different token types - SAML 1.1 vs SAML 2.0