#saml — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #saml, aggregated by home.social.
-
[ Blog ] Configure cross-domain Omnissa Horizon access using Entra ID Guest Accounts
Using Microsoft Entra ID Guest Accounts (B2B) for Omnissa Horizon #SAML authentication provides a clean, elegant solution that eliminates the need to duplicate configurations on your Unified Access Gateways (UAGs).
This architecture is typically deployed when you need http://rviv.ly/OEX7BH #entraid #GuestAccounts #omnissahorizon
-
[ Blog ] Configure cross-domain Omnissa Horizon access using Entra ID Guest Accounts
Using Microsoft Entra ID Guest Accounts (B2B) for Omnissa Horizon #SAML authentication provides a clean, elegant solution that eliminates the need to duplicate configurations on your Unified Access Gateways (UAGs).
This architecture is typically deployed when you need http://rviv.ly/OEX7BH #entraid #GuestAccounts #omnissahorizon
-
[ Blog ] Configure cross-domain Omnissa Horizon access using Entra ID Guest Accounts
Using Microsoft Entra ID Guest Accounts (B2B) for Omnissa Horizon #SAML authentication provides a clean, elegant solution that eliminates the need to duplicate configurations on your Unified Access Gateways (UAGs).
This architecture is typically deployed when you need http://rviv.ly/OEX7BH #entraid #GuestAccounts #omnissahorizon
-
[ Blog ] Configure cross-domain Omnissa Horizon access using Entra ID Guest Accounts
Using Microsoft Entra ID Guest Accounts (B2B) for Omnissa Horizon #SAML authentication provides a clean, elegant solution that eliminates the need to duplicate configurations on your Unified Access Gateways (UAGs).
This architecture is typically deployed when you need http://rviv.ly/OEX7BH #entraid #GuestAccounts #omnissahorizon
-
A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.
-
A SolarWinds Web Help Desk SAML authentication bypass, CVE-2026-28323, scores a critical CVSS 9.8. Update to 2026.2.1 to stay protected.
-
I have a question for the security nerds with knowledge in SAML and Microsoft Entra: We happened to notice that the application web server was presenting the certificate for "foo.example.com" instead of the certificate for the actual URL "https://foo.example.net/login". foo.example.net is CNAME to foo.example.com. Despite this, the login worked just fine the whole time. I’m not sure how serious the issue is, but my gut tells me this probably isn’t such a good idea, right?
-
I have a question for the security nerds with knowledge in SAML and Microsoft Entra: We happened to notice that the application web server was presenting the certificate for "foo.example.com" instead of the certificate for the actual URL "https://foo.example.net/login". foo.example.net is CNAME to foo.example.com. Despite this, the login worked just fine the whole time. I’m not sure how serious the issue is, but my gut tells me this probably isn’t such a good idea, right?
-
I have a question for the security nerds with knowledge in SAML and Microsoft Entra: We happened to notice that the application web server was presenting the certificate for "foo.example.com" instead of the certificate for the actual URL "https://foo.example.net/login". foo.example.net is CNAME to foo.example.com. Despite this, the login worked just fine the whole time. I’m not sure how serious the issue is, but my gut tells me this probably isn’t such a good idea, right?
-
I have a question for the security nerds with knowledge in SAML and Microsoft Entra: We happened to notice that the application web server was presenting the certificate for "foo.example.com" instead of the certificate for the actual URL "https://foo.example.net/login". foo.example.net is CNAME to foo.example.com. Despite this, the login worked just fine the whole time. I’m not sure how serious the issue is, but my gut tells me this probably isn’t such a good idea, right?
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
Need to generate and sign a SAML AuthnRequest for HTTP-Redirect binding? This snippet uses OpenSSL and xmlstarlet to create the signed XML with AssertionConsumerServiceURL and ForceAuthn.
#saml #snippet #ValtersIThttps://www.valtersit.com/vault/saml-authnrequest-generation-and-signing-with-openssl-99af97/
-
CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! https://radar.offseq.com/threat/cve-2026-49454-cwe-287-improper-authentication-in--d880f0af884dcf13 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec
-
CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! https://radar.offseq.com/threat/cve-2026-49454-cwe-287-improper-authentication-in--d880f0af884dcf13 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec
-
CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! https://radar.offseq.com/threat/cve-2026-49454-cwe-287-improper-authentication-in--d880f0af884dcf13 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec
-
CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! https://radar.offseq.com/threat/cve-2026-49454-cwe-287-improper-authentication-in--d880f0af884dcf13 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec
-
#SAML Single Log Out is finally looking good for #tryton … Still some ironing to do wrt the log in window that should reappear after a log out. And then there's the issue of the GTK client to tackle.
SAML libraries in python aren't exactly well documented but I think I had some success in untangeling and matching the code of pysaml2 and the the actual SAML2 norm and protocol.
https://foss.heptapod.net/tryton/tryton/-/merge_requests/3421
-
#SAML Single Log Out is finally looking good for #tryton … Still some ironing to do wrt the log in window that should reappear after a log out. And then there's the issue of the GTK client to tackle.
SAML libraries in python aren't exactly well documented but I think I had some success in untangeling and matching the code of pysaml2 and the the actual SAML2 norm and protocol.
https://foss.heptapod.net/tryton/tryton/-/merge_requests/3421
-
#SAML Single Log Out is finally looking good for #tryton … Still some ironing to do wrt the log in window that should reappear after a log out. And then there's the issue of the GTK client to tackle.
SAML libraries in python aren't exactly well documented but I think I had some success in untangeling and matching the code of pysaml2 and the the actual SAML2 norm and protocol.
https://foss.heptapod.net/tryton/tryton/-/merge_requests/3421
-
#SAML Single Log Out is finally looking good for #tryton … Still some ironing to do wrt the log in window that should reappear after a log out. And then there's the issue of the GTK client to tackle.
SAML libraries in python aren't exactly well documented but I think I had some success in untangeling and matching the code of pysaml2 and the the actual SAML2 norm and protocol.
https://foss.heptapod.net/tryton/tryton/-/merge_requests/3421
-
I wonder how do people test their #saml implementations. Do they run locally an IdP to test for multiple scenarios? Also I don't know how I'm supposed to write tests for that.
-
I wonder how do people test their #saml implementations. Do they run locally an IdP to test for multiple scenarios? Also I don't know how I'm supposed to write tests for that.
-
I wonder how do people test their #saml implementations. Do they run locally an IdP to test for multiple scenarios? Also I don't know how I'm supposed to write tests for that.
-
I wonder how do people test their #saml implementations. Do they run locally an IdP to test for multiple scenarios? Also I don't know how I'm supposed to write tests for that.
-
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
On top of the #uppsala #XML library and #bergshamra #xmlsec library I have #gamlastan, the #SAML library https://crates.io/crates/gamlastan #identity
Finally I can work on the applications I needed.
-
On top of the #uppsala #XML library and #bergshamra #xmlsec library I have #gamlastan, the #SAML library https://crates.io/crates/gamlastan #identity
Finally I can work on the applications I needed.
-
On top of the #uppsala #XML library and #bergshamra #xmlsec library I have #gamlastan, the #SAML library https://crates.io/crates/gamlastan #identity
Finally I can work on the applications I needed.
-
On top of the #uppsala #XML library and #bergshamra #xmlsec library I have #gamlastan, the #SAML library https://crates.io/crates/gamlastan #identity
Finally I can work on the applications I needed.
-
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
For whoever likes to authenticate to their #Nextcloud instance with some overengineered protocols, namely SAML. There is a new release of the user_saml app with some small bugfixes and better debug outputs when something goes wrong.
Cheers!
https://github.com/nextcloud-releases/user_saml/releases/tag/v8.1.0