The Identity Portal is not working with SAML encryption assertion turned on.
When the Keycloak(IdP) is configured with Sign Doc/AuthRequest=ON and Sign Assertion=ON, it does not work with the IdentityPortal(SP) that has Request Decryption key turned ON.
The issue here is that when SAML encryption assertion is turned ON, by right, it should also work together when Sign doc/authRequest=ON & Sign Assertion=ON.
Vapp 14.5 GA with IP, IM, PS, CS, US deployed(Backend using MSSQL db).
critical security risk for their high-priority customers
To address this issue, the Engineering team has provided a patch HF_IP-14.5.0-20260220140226-SAML_ENCRYPTION_FIX.tgz.gpg.
Please raise a support ticket and request the HF
Ref# DE659928