SAML | Signed AuthN requests
In a SAML request flow, Cloudflare Access functions as the service provider (SP) to the identity provider (IdP). Cloudflare Access sends a SAML request to your IdP. The signing certificate that you upload from your SAML provider verifies the response.
In some cases, administrators need to verify that the request from the SP is authentic. By validating both the requests from the SP and the responses from the IdP, teams can ensure that operations in the SAML relationship are signed in both directions.
Cloudflare Access supports this requirement in the form of Signed AuthN requests. When enabled, Access sends a signature embedded in an HTTP POST request that contains the AuthN details.
Set up Signed AuthN requests
To set up Signed AuthN requests:
On the Teams dashboard, navigate to Configuration > Authentication.
Under Login methods, click + Add.
Choose SAML on the next page.
Complete the fields in the dialog.
Go to this URL to find the certificate:
Cloudflare Access uses a certificate that includes the following 2 distinguished name fields:
Issuer Distinguished Name –
CN=cloudflareaccess.com, C=US, ST=Texas, L=Austin, O=Cloudflare
Subject Distinguished Name –
CN=*.cloudflareaccess.com, C=US, ST=Texas, L=Austin, O=Cloudflare
Most IdP configurations require 3 components to enforce AuthN signature verification:
Certificate subject distinguished name
This is an example format: