Engineering
Why Unsigned SAML Is Dangerous
Your ACS endpoint is a URL on the public internet that accepts a POST with a Base64-encoded XML document and, if it likes what it reads, logs someone in.
Engineering
Your ACS endpoint is a URL on the public internet that accepts a POST with a Base64-encoded XML document and, if it likes what it reads, logs someone in.
Engineering
Somewhere in your SAML integration documentation there is probably a sentence like "assertions must be signed and encrypted." Somewhere in a customer's security questionnaire there is a question asking whether you support assertion encryption, and the only commercially viable answer is yes.
Engineering
These three get compared constantly, usually in a table that lists which one uses XML and which one uses JSON. That comparison is technically accurate and almost useless, because it implies the three are alternatives competing for the same job.
Engineering
At 08:47 on a Monday, 4,000 people at one of your customers cannot log in. Every SSO attempt fails with a signature validation error.
Engineering
Put the two flows side by side at the protocol level and they look almost identical. Same assertion format. Same XML signature over the same elements. Same trust model — you configured the IdP's certificate, you check the signature, you accept the statement. If you diffed two Response documents from
Engineering
SAML errors are uninformative on purpose, and knowing why is the first step to debugging them.
IAM
A few years ago, I was involved in evaluating an Identity and Access Management (IAM) platform for a SaaS application. The RFP was straightforward. Supports multi-tenancy. Every vendor answered Yes. The demos looked convincing. Implementation told a different story. One product required globally unique usernames. Another shared signing certificates across
SAML
A free browser extension that makes SAML failures easy to capture, understand, and share — built for the people who have to send the support ticket, not just the engineers who read it.