home.social

#saml — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #saml, aggregated by home.social.

fetched live
  1. I have a question for the security nerds with knowledge in SAML and Microsoft Entra: We happened to notice that the application web server was presenting the certificate for "foo.example.com" instead of the certificate for the actual URL "foo.example.net/login". foo.example.net is CNAME to foo.example.com. Despite this, the login worked just fine the whole time. I’m not sure how serious the issue is, but my gut tells me this probably isn’t such a good idea, right?

    #microsoft #saml #entra #ssl

  2. CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE202615013 #SAML #Vuln

  3. Need to generate and sign a SAML AuthnRequest for HTTP-Redirect binding? This snippet uses OpenSSL and xmlstarlet to create the signed XML with AssertionConsumerServiceURL and ForceAuthn.

    #saml #snippet #ValtersIT

    valtersit.com/vault/saml-authn

  4. This week I am getting intense amount #Identity knowledge from my amazing teammates in #SUNET. So many things are becoming clearer!!! #Sweden #SAML #OIDC

  5. This week I am getting intense amount #Identity knowledge from my amazing teammates in #SUNET. So many things are becoming clearer!!! #Sweden #SAML #OIDC

  6. CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! radar.offseq.com/threat/cve-20 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec

  7. #SAML Single Log Out is finally looking good for #tryton … Still some ironing to do wrt the log in window that should reappear after a log out. And then there's the issue of the GTK client to tackle.

    SAML libraries in python aren't exactly well documented but I think I had some success in untangeling and matching the code of pysaml2 and the the actual SAML2 norm and protocol.

    foss.heptapod.net/tryton/tryto

  8. I wonder how do people test their #saml implementations. Do they run locally an IdP to test for multiple scenarios? Also I don't know how I'm supposed to write tests for that.

    #pleaseboost #testing

  9. #Jellyfin #SSO plugin github.com/9p4/jellyfin-plugin has been archived ("I'm tired of working on this after all the years", which, fair).
    But it looks like it was forked into github.com/eddymoulton/jellyfi and development contiues, limiting itself to #OIDC but without #SAML
    Nice!

    #SelfHost #SelfHosting #HomeLab

  10. #Jellyfin #SSO plugin github.com/9p4/jellyfin-plugin has been archived ("I'm tired of working on this after all the years", which, fair).
    But it looks like it was forked into github.com/eddymoulton/jellyfi and development contiues, limiting itself to #OIDC but without #SAML
    Nice!

    #SelfHost #SelfHosting #HomeLab

  11. 🌟 LemonLDAP::NG 2.23 released!

    ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration

    ➡️ projects.ow2.org/view/lemonlda

    @ow2 @PerlRakuFoundation

  12. For whoever likes to authenticate to their #Nextcloud instance with some overengineered protocols, namely SAML. There is a new release of the user_saml app with some small bugfixes and better debug outputs when something goes wrong.

    Cheers!

    github.com/nextcloud-releases/

    #SAML

  13. For whoever likes to authenticate to their #Nextcloud instance with some overengineered protocols, namely SAML. There is a new release of the user_saml app with some small bugfixes and better debug outputs when something goes wrong.

    Cheers!

    github.com/nextcloud-releases/

    #SAML

  14. ⚠️ HIGH severity: CVE-2026-5343 in Drupal SAML SSO - Service Provider (pre-3.1.4) allows privilege escalation via improper exception checks. No patch or exploits yet. Monitor advisories for updates. radar.offseq.com/threat/cve-20 #OffSeq #Drupal #Vuln #SAML

  15. Интеграция SAP NetWeaver AS Java с Keycloak: SAML, 2FA и неожиданные проблемы

    Хабр, привет! В последнее время обсуждать миграцию с продуктов SAP – это база. Однако для многих компаний эти системы пока остаются ключевыми. Типичная защита периметра: «свои» внутри, «чужие» снаружи. Но бывает инверсия. Заказчик открывает SAP NetWeaver AS Java в большой мир. SAML в этой системе активируется быстрее, чем вы моргнете — буквально в два клика. Но если на том конце провода не дремлет злоумышленник, а у вас нет 2FA… считайте, что ключи от дома вы спрятали под ковриком. Мы столкнулись с этой болью на проекте у одного из заказчиков. Нужно было настроить двухфакторную аутентификацию. И вот тут начались нюансы. В этом материале мы опишем настройку интеграции портала SAP NetWeaver AS Java с внешним Identity Provider (IdP) — Keycloak — с реализацией двухфакторной аутентификации (2FA). До нашего вмешательства аутентификация происходила напрямую в SAP-системе. Сама настройка и реализация несложные, однако есть несколько моментов, с которыми мы столкнулись на практике, и при этом не нашли достаточно подробного описания в документации. Далее кратко рассмотрим процесс настройки и разберем возникшие проблемы.

    habr.com/ru/companies/jetinfos

    #sap #saml #keycloak #2faаутентификация #2fa

  16. Особенности архитектуры сетевой системы защиты информации с применением Keycloak

    Развитие цифровых сервисов, облачных платформ, распределённых корпоративных систем и API-инфраструктуры приводит к существенному усложнению задач обеспечения информационной безопасности. В современных условиях защита информации уже не может ограничиваться только периметровыми средствами, такими как межсетевые экраны и системы фильтрации трафика. Существенное значение приобретают механизмы идентификации субъектов доступа, централизованного управления правами, а также мониторинга и аудита действий пользователей и сервисов. Одним из перспективных подходов к решению указанных задач является внедрение систем класса Identity and Access Management (IAM), обеспечивающих централизованную аутентификацию, авторизацию и управление учётными данными. Среди свободно распространяемых решений данного класса важное место занимает Keycloak - платформа с открытым исходным кодом, предназначенная для организации единого входа, федерации пользователей и управления доступом на основе стандартных протоколов безопасности. Актуальность применения Keycloak обусловлена тем, что данная система позволяет унифицировать процессы аутентификации в гетерогенной ИТ-среде, обеспечить поддержку многофакторной аутентификации, интеграцию с LDAP/Active Directory, а также централизованное управление ролями и политиками доступа. При этом архитектурные особенности внедрения Keycloak требуют отдельного анализа, поскольку речь идёт о критически важном компоненте сетевой системы защиты информации. Место Keycloak в архитектуре сетевой защиты информации

    habr.com/ru/articles/1026198/

    #keycloak #защита_информации #сетевая_безопасность #аутентификация #авторизация #iam #sso #oauth_20 #openid_connect #saml

  17. Has your company recently asked you to implement #SAML 2.0? Worried about the prospect of implementing the 20-year-old protocol?

    Come check out how to implement SAML 2.0 into Duende IdentityServer. #dotnet #saml #security #aspnetcore

    🙏 boosts appreciated #livestream

    youtube.com/watch?v=o_tGJ9KHdns

  18. Has your company recently asked you to implement #SAML 2.0? Worried about the prospect of implementing the 20-year-old protocol?

    Come check out how to implement SAML 2.0 into Duende IdentityServer. #dotnet #saml #security #aspnetcore

    🙏 boosts appreciated #livestream

    youtube.com/watch?v=o_tGJ9KHdns

  19. 👍 LemonLDAP::NG 2.22.3, 2.21.4 and 2.16.8 released!

    🔐 Security issue with Nginx fixed, please read upgrade notes and apply recommended configuration changes!

    🔗 projects.ow2.org/view/lemonlda

  20. 👍 LemonLDAP::NG 2.22.3, 2.21.4 and 2.16.8 released!

    🔐 Security issue with Nginx fixed, please read upgrade notes and apply recommended configuration changes!

    🔗 projects.ow2.org/view/lemonlda

    #SSO #IAM #LDAP #CAS #SAML #OIDC

  21. SAML 2.0 is een veilige, bewezen manier om authenticatie mogelijk te maken.

    DigiD, eHerkenning en eIDAS zijn erop gebouwd en op die manier vinden er per dag miljoenen logins plaats op basis van deze techniek.

    Toch is SAML niet ideaal in zowel technisch opzicht als op het vlak van gebruiksvriendelijkheid.

    SAML is in de kern ontworpen voor browser-based SSO, niet voor bijvoorbeeld API beveiliging.

    Er is een standaard die dit intuïtiever doet: OpenID Connect.

    #openidconnect #saml #digid

  22. SAML 2.0 is een veilige, bewezen manier om authenticatie mogelijk te maken.

    DigiD, eHerkenning en eIDAS zijn erop gebouwd en op die manier vinden er per dag miljoenen logins plaats op basis van deze techniek.

    Toch is SAML niet ideaal in zowel technisch opzicht als op het vlak van gebruiksvriendelijkheid.

    SAML is in de kern ontworpen voor browser-based SSO, niet voor bijvoorbeeld API beveiliging.

    Er is een standaard die dit intuïtiever doet: OpenID Connect.

    #openidconnect #saml #digid

  23. Dear LazyFedi, I'm looking for a #SaaS solution that acts as a kind of #SSO multiplexer.

    I have 4 Microsoft tenancies, and I can map users to tenancies by email address. What I want is something that acts as a single frontend to all of them for #SAML / #OpenID logins.

    I need this to set up SSO for some of our other SaaS products which only support one provider.

    (NB: this needs to be SaaS, UK/EU based. I'm not able to self host anything in this context)

    #Authentication #AuthN

  24. Dear LazyFedi, I'm looking for a #SaaS solution that acts as a kind of #SSO multiplexer.

    I have 4 Microsoft tenancies, and I can map users to tenancies by email address. What I want is something that acts as a single frontend to all of them for #SAML / #OpenID logins.

    I need this to set up SSO for some of our other SaaS products which only support one provider.

    (NB: this needs to be SaaS, UK/EU based. I'm not able to self host anything in this context)

    #Authentication #AuthN

  25. Along with the #XML library I also have a #rust #rustlang #xmlsec replacement library crates.io/crates/bergshamra Is there anyone in my timeline who can play around/test/verify? #security #saml

  26. Along with the #XML library I also have a #rust #rustlang #xmlsec replacement library crates.io/crates/bergshamra Is there anyone in my timeline who can play around/test/verify? #security #saml

  27. @developer
    Mooie blog! De combinatie van OpenID.NLGov en SAML staat onder de noemer Authenticatie-standaarden op de 'pas toe of leg uit'-lijst met verplichte open standaarden: forumstandaardisatie.nl/open-s

    Het toepassingsgebied (dat de reikwijdte van de verplichting bepaalt) is zo gedefinieerd dat een identity provider (zoals DigiD en eHerkenning) voor ieder van beide standaarden een koppelvlak aanbiedt en dat dienstaanbieders de keuze hebben via welke ze aansluiten.

    #SAML #OpenID #OIDC #government

  28. @developer
    Mooie blog! De combinatie van OpenID.NLGov en SAML staat onder de noemer Authenticatie-standaarden op de 'pas toe of leg uit'-lijst met verplichte open standaarden: forumstandaardisatie.nl/open-s

    Het toepassingsgebied (dat de reikwijdte van de verplichting bepaalt) is zo gedefinieerd dat een identity provider (zoals DigiD en eHerkenning) voor ieder van beide standaarden een koppelvlak aanbiedt en dat dienstaanbieders de keuze hebben via welke ze aansluiten.

    #SAML #OpenID #OIDC #government

  29. 🔐 SAML heeft ons ver gebracht, maar de wereld is niet meer alleen browser-based. Onze collega Floris Deutekom legt uit waarom OpenID Connect een volwaardig alternatief zou moeten worden voor DigiD, eHerkenning en eIDAS. Niet als vervanging, maar als aanvulling voor moderne, API-gedreven dienstverlening.

    developer.overheid.nl/blog/202

    #OpenIDConnect #OIDC #DigiD #eHerkenning #eIDAS #DigitaleOverheid #API #SAML

  30. 🔐 SAML heeft ons ver gebracht, maar de wereld is niet meer alleen browser-based. Onze collega Floris Deutekom legt uit waarom OpenID Connect een volwaardig alternatief zou moeten worden voor DigiD, eHerkenning en eIDAS. Niet als vervanging, maar als aanvulling voor moderne, API-gedreven dienstverlening.

    developer.overheid.nl/blog/202

    #OpenIDConnect #OIDC #DigiD #eHerkenning #eIDAS #DigitaleOverheid #API #SAML

  31. Hey y'all 👋 I'm Emily, but friends call me Em — spelled like the dash! Guess it's time for an #intro post.

    I'm a software engineer by day, and I lead a team working at the intersection of digital identity and usability.

    Functionally, this means I grew up playing around in Macromedia Fireworks and learning to make websites with the middle school librarian, and nowadays I know far too much about #SAML, #MFA, #OIDC, #Passkeys, and go to lots of meetings 😮‍💨

    I love music (playing or listening), photography, and getting outdoors! Teaching makes me incredibly happy.

    I'm also a diehard #avgeek, licensed #amateurradio operator, uhhhh, I know a lot about transit busses? Tell me about your special interests plz!

    Currently learning C++ because I'm insane, and learning to draw with #Krita because it makes me happy.

  32. 🚩 CRITICAL: CVE-2025-66568 in ruby-saml (<1.18.0) allows SAML signature bypass via XML canonicalization flaw. Patch to 1.18.0+ ASAP to protect SSO! Details: radar.offseq.com/threat/cve-20 #OffSeq #SAML #Ruby #Vuln

  33. Has anyone done some kind of SSO / SAML auth thing which supports "N of M" type authentication?

    Like, I want to log into a shared Fedi account to post something; I log into my SSO provider as usual, and another member of the same group needs to "approve" before I get a login ticket for the target account.

    The intended market for this would be organisations who don't want to share a password for an account, or who want some oversight on how it's used.

    #SSO #SAML #Authentication

  34. I wrote a new blog post about PassBeyond, a lightweight SAML SP + reverse proxy to add SSO to self-hosted apps that don’t support modern authentication. It handles SAML, creates JWT sessions, and forwards identity via headers - no code changes needed.

    🔗 blog.bella.network/securing-we

    #SAML #SSO #SelfHosted #Security #Sysadmim #DevOps #Golang