Amazon Workspaces - Cert-based authentication on Ubuntu Workspaces & support for non-hardcoded audiences in SAML integrations

0
  1. Is certificate-based authentication coming to Ubuntu Workspaces?

Certificate-based auth: a. I understand that this cannot work with Azure AD DS, since the DCs deployed by this service do not support Certificate Services ruling out the use of smart card authentication, is this correct? b. Requirement for certificate-based auth coming to Ubuntu  Passwords become irrelevant and the key reason why we need to tie into Azure AD / AD DS goes away.  If we don’t need AD DS, then the need for the rest of the Azure side goes away and we could run an AWS-managed AD with Certificate Services enabled.

  1. Is support for non-hardcoded audiences in SAML integrations planned to be released?

a. Reason for ask: o Each deployment of Workspaces has its own SAML integration and a unique relay state endpoint we need to hit on the way back from Azure AD o Different regions => different endpoints o The above really means we need multiple SAML apps in our IDP, one per region/deployment. o However, the SAML audience/EntityID is hardcoded on the AWS side and is always urn:amazon:webservices. o Azure AD really does not like this as it enforces EntityIDs to be unique within a tenant, implying we can’t have two SAML apps for Workspaces. o We could rely on AWS Identity Centre, but layering two IDPs isn’t something we want to do as it’s a potentially a lot of complexity and security headaches

Any help on these challenges are much appreciated!

AWS
已提问 8 个月前374 查看次数
1 回答
0
已接受的回答
  1. Is certificate-based authentication coming to Ubuntu Workspaces?
  • We can't share any roadmap information on a public form. CBA is supported with Windows WorkSpaces on WorkSpaces Streaming Protocol (WSP) bundles using the latest client applications.
  1. Is support for non-hardcoded audiences in SAML integrations planned to be released?
profile pictureAWS
已回答 8 个月前
  • Hi Jeremy, thanks for the quick response. I'm happy to share my alias if point 1 is something we can share with a customer under NDA?

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则