#saml — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #saml, aggregated by home.social.
-
I have a question for the security nerds with knowledge in SAML and Microsoft Entra: We happened to notice that the application web server was presenting the certificate for "foo.example.com" instead of the certificate for the actual URL "https://foo.example.net/login". foo.example.net is CNAME to foo.example.com. Despite this, the login worked just fine the whole time. I’m not sure how serious the issue is, but my gut tells me this probably isn’t such a good idea, right?
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23.1 released!
ℹ️ Certificate based LDAP authentication and some bug fixes
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-1-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
CVE-2026-15013 | CRITICAL vuln in cyberlord92 SAML SSO Login (≤5.4.3): Signature verification flaw enables authentication bypass & admin account takeover. Disable plugin until patched. https://radar.offseq.com/threat/cve-2026-15013-cwe-347-improper-verification-of-cr-9c8a5e33bdf9b83d #OffSeq #WordPress #CVE202615013 #SAML #Vuln
-
Need to generate and sign a SAML AuthnRequest for HTTP-Redirect binding? This snippet uses OpenSSL and xmlstarlet to create the signed XML with AssertionConsumerServiceURL and ForceAuthn.
#saml #snippet #ValtersIThttps://www.valtersit.com/vault/saml-authnrequest-generation-and-signing-with-openssl-99af97/
-
CVE-2026-49454: szTheory relyra (<1.2.0) has a CRITICAL SAML authentication flaw — improper signature verification lets attackers forge responses & impersonate users. Fixed in v1.2.0. Patch now! https://radar.offseq.com/threat/cve-2026-49454-cwe-287-improper-authentication-in--d880f0af884dcf13 #OffSeq #CVE202649454 #SAML #Elixir #InfoSec
-
#SAML Single Log Out is finally looking good for #tryton … Still some ironing to do wrt the log in window that should reappear after a log out. And then there's the issue of the GTK client to tackle.
SAML libraries in python aren't exactly well documented but I think I had some success in untangeling and matching the code of pysaml2 and the the actual SAML2 norm and protocol.
https://foss.heptapod.net/tryton/tryton/-/merge_requests/3421
-
I wonder how do people test their #saml implementations. Do they run locally an IdP to test for multiple scenarios? Also I don't know how I'm supposed to write tests for that.
-
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
#Jellyfin #SSO plugin https://github.com/9p4/jellyfin-plugin-sso has been archived ("I'm tired of working on this after all the years", which, fair).
But it looks like it was forked into https://github.com/eddymoulton/jellyfin-plugin-oidc and development contiues, limiting itself to #OIDC but without #SAML
Nice! -
On top of the #uppsala #XML library and #bergshamra #xmlsec library I have #gamlastan, the #SAML library https://crates.io/crates/gamlastan #identity
Finally I can work on the applications I needed.
-
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
🌟 LemonLDAP::NG 2.23 released!
ℹ️ Improvements on CAS/SAML/OIDC, on 2FA management, hooks, Crowdsec and configuration
➡️ https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-23-0-is-out/
#IAM #SSO #CAS #SAML #OpenIDConnect #OpenSource #LogicielLibre #Perl
-
For whoever likes to authenticate to their #Nextcloud instance with some overengineered protocols, namely SAML. There is a new release of the user_saml app with some small bugfixes and better debug outputs when something goes wrong.
Cheers!
https://github.com/nextcloud-releases/user_saml/releases/tag/v8.1.0
-
For whoever likes to authenticate to their #Nextcloud instance with some overengineered protocols, namely SAML. There is a new release of the user_saml app with some small bugfixes and better debug outputs when something goes wrong.
Cheers!
https://github.com/nextcloud-releases/user_saml/releases/tag/v8.1.0
-
⚠️ HIGH severity: CVE-2026-5343 in Drupal SAML SSO - Service Provider (pre-3.1.4) allows privilege escalation via improper exception checks. No patch or exploits yet. Monitor advisories for updates. https://radar.offseq.com/threat/cve-2026-5343-cwe-754-improper-check-for-unusual-o-7182465d #OffSeq #Drupal #Vuln #SAML
-
Интеграция SAP NetWeaver AS Java с Keycloak: SAML, 2FA и неожиданные проблемы
Хабр, привет! В последнее время обсуждать миграцию с продуктов SAP – это база. Однако для многих компаний эти системы пока остаются ключевыми. Типичная защита периметра: «свои» внутри, «чужие» снаружи. Но бывает инверсия. Заказчик открывает SAP NetWeaver AS Java в большой мир. SAML в этой системе активируется быстрее, чем вы моргнете — буквально в два клика. Но если на том конце провода не дремлет злоумышленник, а у вас нет 2FA… считайте, что ключи от дома вы спрятали под ковриком. Мы столкнулись с этой болью на проекте у одного из заказчиков. Нужно было настроить двухфакторную аутентификацию. И вот тут начались нюансы. В этом материале мы опишем настройку интеграции портала SAP NetWeaver AS Java с внешним Identity Provider (IdP) — Keycloak — с реализацией двухфакторной аутентификации (2FA). До нашего вмешательства аутентификация происходила напрямую в SAP-системе. Сама настройка и реализация несложные, однако есть несколько моментов, с которыми мы столкнулись на практике, и при этом не нашли достаточно подробного описания в документации. Далее кратко рассмотрим процесс настройки и разберем возникшие проблемы.
https://habr.com/ru/companies/jetinfosystems/articles/1034088/
-
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
One Open-source Project Daily
Simple, unobtrusive authentication for Node.js.
https://github.com/jaredhanson/passport
#1ospd #opensource #express #nodejs #oauth #oauth2 #openid #openidconnect #passport #saml -
Особенности архитектуры сетевой системы защиты информации с применением Keycloak
Развитие цифровых сервисов, облачных платформ, распределённых корпоративных систем и API-инфраструктуры приводит к существенному усложнению задач обеспечения информационной безопасности. В современных условиях защита информации уже не может ограничиваться только периметровыми средствами, такими как межсетевые экраны и системы фильтрации трафика. Существенное значение приобретают механизмы идентификации субъектов доступа, централизованного управления правами, а также мониторинга и аудита действий пользователей и сервисов. Одним из перспективных подходов к решению указанных задач является внедрение систем класса Identity and Access Management (IAM), обеспечивающих централизованную аутентификацию, авторизацию и управление учётными данными. Среди свободно распространяемых решений данного класса важное место занимает Keycloak - платформа с открытым исходным кодом, предназначенная для организации единого входа, федерации пользователей и управления доступом на основе стандартных протоколов безопасности. Актуальность применения Keycloak обусловлена тем, что данная система позволяет унифицировать процессы аутентификации в гетерогенной ИТ-среде, обеспечить поддержку многофакторной аутентификации, интеграцию с LDAP/Active Directory, а также централизованное управление ролями и политиками доступа. При этом архитектурные особенности внедрения Keycloak требуют отдельного анализа, поскольку речь идёт о критически важном компоненте сетевой системы защиты информации. Место Keycloak в архитектуре сетевой защиты информации
https://habr.com/ru/articles/1026198/
#keycloak #защита_информации #сетевая_безопасность #аутентификация #авторизация #iam #sso #oauth_20 #openid_connect #saml
-
Has your company recently asked you to implement #SAML 2.0? Worried about the prospect of implementing the 20-year-old protocol?
Come check out how to implement SAML 2.0 into Duende IdentityServer. #dotnet #saml #security #aspnetcore
🙏 boosts appreciated #livestream
-
Has your company recently asked you to implement #SAML 2.0? Worried about the prospect of implementing the 20-year-old protocol?
Come check out how to implement SAML 2.0 into Duende IdentityServer. #dotnet #saml #security #aspnetcore
🙏 boosts appreciated #livestream
-
👍 LemonLDAP::NG 2.22.3, 2.21.4 and 2.16.8 released!
🔐 Security issue with Nginx fixed, please read upgrade notes and apply recommended configuration changes!
🔗 https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-22-3-is-out
-
👍 LemonLDAP::NG 2.22.3, 2.21.4 and 2.16.8 released!
🔐 Security issue with Nginx fixed, please read upgrade notes and apply recommended configuration changes!
🔗 https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-22-3-is-out
-
SAML 2.0 is een veilige, bewezen manier om authenticatie mogelijk te maken.
DigiD, eHerkenning en eIDAS zijn erop gebouwd en op die manier vinden er per dag miljoenen logins plaats op basis van deze techniek.
Toch is SAML niet ideaal in zowel technisch opzicht als op het vlak van gebruiksvriendelijkheid.
SAML is in de kern ontworpen voor browser-based SSO, niet voor bijvoorbeeld API beveiliging.
Er is een standaard die dit intuïtiever doet: OpenID Connect.
-
SAML 2.0 is een veilige, bewezen manier om authenticatie mogelijk te maken.
DigiD, eHerkenning en eIDAS zijn erop gebouwd en op die manier vinden er per dag miljoenen logins plaats op basis van deze techniek.
Toch is SAML niet ideaal in zowel technisch opzicht als op het vlak van gebruiksvriendelijkheid.
SAML is in de kern ontworpen voor browser-based SSO, niet voor bijvoorbeeld API beveiliging.
Er is een standaard die dit intuïtiever doet: OpenID Connect.
-
New post on my #blog about #selfhost of #keycloak and #sonarqube to help you improve the quality of your code. #SAML #Authentication #Security https://blog.devenphillips.dev/posts/sonarqube-with-saml-auth.html
-
New post on my #blog about #selfhost of #keycloak and #sonarqube to help you improve the quality of your code. #SAML #Authentication #Security https://blog.devenphillips.dev/posts/sonarqube-with-saml-auth.html
-
Dear LazyFedi, I'm looking for a #SaaS solution that acts as a kind of #SSO multiplexer.
I have 4 Microsoft tenancies, and I can map users to tenancies by email address. What I want is something that acts as a single frontend to all of them for #SAML / #OpenID logins.
I need this to set up SSO for some of our other SaaS products which only support one provider.
(NB: this needs to be SaaS, UK/EU based. I'm not able to self host anything in this context)
-
Dear LazyFedi, I'm looking for a #SaaS solution that acts as a kind of #SSO multiplexer.
I have 4 Microsoft tenancies, and I can map users to tenancies by email address. What I want is something that acts as a single frontend to all of them for #SAML / #OpenID logins.
I need this to set up SSO for some of our other SaaS products which only support one provider.
(NB: this needs to be SaaS, UK/EU based. I'm not able to self host anything in this context)
-
RE: https://toots.dgplug.org/@kushal/116126397672236446
Added a section on #Security #hardening #XSW #XML #SAML in this release.
-
RE: https://toots.dgplug.org/@kushal/116126397672236446
Added a section on #Security #hardening #XSW #XML #SAML in this release.
-
@developer
Mooie blog! De combinatie van OpenID.NLGov en SAML staat onder de noemer Authenticatie-standaarden op de 'pas toe of leg uit'-lijst met verplichte open standaarden: https://www.forumstandaardisatie.nl/open-standaarden/authenticatie-standaardenHet toepassingsgebied (dat de reikwijdte van de verplichting bepaalt) is zo gedefinieerd dat een identity provider (zoals DigiD en eHerkenning) voor ieder van beide standaarden een koppelvlak aanbiedt en dat dienstaanbieders de keuze hebben via welke ze aansluiten.
-
@developer
Mooie blog! De combinatie van OpenID.NLGov en SAML staat onder de noemer Authenticatie-standaarden op de 'pas toe of leg uit'-lijst met verplichte open standaarden: https://www.forumstandaardisatie.nl/open-standaarden/authenticatie-standaardenHet toepassingsgebied (dat de reikwijdte van de verplichting bepaalt) is zo gedefinieerd dat een identity provider (zoals DigiD en eHerkenning) voor ieder van beide standaarden een koppelvlak aanbiedt en dat dienstaanbieders de keuze hebben via welke ze aansluiten.
-
🔐 SAML heeft ons ver gebracht, maar de wereld is niet meer alleen browser-based. Onze collega Floris Deutekom legt uit waarom OpenID Connect een volwaardig alternatief zou moeten worden voor DigiD, eHerkenning en eIDAS. Niet als vervanging, maar als aanvulling voor moderne, API-gedreven dienstverlening.
https://developer.overheid.nl/blog/2026/02/11/oidc-voor-nederlanse-identiteitsdiensten
#OpenIDConnect #OIDC #DigiD #eHerkenning #eIDAS #DigitaleOverheid #API #SAML
-
🔐 SAML heeft ons ver gebracht, maar de wereld is niet meer alleen browser-based. Onze collega Floris Deutekom legt uit waarom OpenID Connect een volwaardig alternatief zou moeten worden voor DigiD, eHerkenning en eIDAS. Niet als vervanging, maar als aanvulling voor moderne, API-gedreven dienstverlening.
https://developer.overheid.nl/blog/2026/02/11/oidc-voor-nederlanse-identiteitsdiensten
#OpenIDConnect #OIDC #DigiD #eHerkenning #eIDAS #DigitaleOverheid #API #SAML
-
#Trump #EPA reportedly seeks to revoke landmark air pollution
https://kensbookinfo.blogspot.com/p/etc-varied.html#12#ChatGPT and other #AI models believe medical misinformation
https://kensbookinfo.blogspot.com/p/etc-continents.html#EuropeWhat’s happening Tuesday around #CarsonCity
https://kensbookinfo.blogspot.com/p/us-capitals.html#CarsonCity#Macron's statements about dialogue with #Russia aimed
https://kensbookinfo.blogspot.com/p/etc.html#Russiabacklash as #US national monuments conform to #Trump’s
https://kensbookinfo.blogspot.com/p/uk.html#9#SAML vs SSO
https://kensbookinfo.blogspot.com/p/infotech.html#101 -
🦊 New post: Modernizing .NET – Part 9
SAML SSO migration to ITfoxtec in .NET Core.
Config, response handling, logging — all covered.
Read it → https://medium.com/@michael.kopt/modernizing-net-part-9-migrating-saml-sso-to-itfoxtec-44133b003702
#DotNet #SAML #SSO #ITfoxtec #CSharp #Identity #ASPNet #ASPNetCore #Linux #DotNetCore #DotNet8 #DotNet9 #DotNet10 -
Hey y'all 👋 I'm Emily, but friends call me Em — spelled like the dash! Guess it's time for an #intro post.
I'm a software engineer by day, and I lead a team working at the intersection of digital identity and usability.
Functionally, this means I grew up playing around in Macromedia Fireworks and learning to make websites with the middle school librarian, and nowadays I know far too much about #SAML, #MFA, #OIDC, #Passkeys, and go to lots of meetings 😮💨
I love music (playing or listening), photography, and getting outdoors! Teaching makes me incredibly happy.
I'm also a diehard #avgeek, licensed #amateurradio operator, uhhhh, I know a lot about transit busses? Tell me about your special interests plz!
Currently learning C++ because I'm insane, and learning to draw with #Krita because it makes me happy.
-
🚩 CRITICAL: CVE-2025-66568 in ruby-saml (<1.18.0) allows SAML signature bypass via XML canonicalization flaw. Patch to 1.18.0+ ASAP to protect SSO! Details: https://radar.offseq.com/threat/cve-2025-66568-cwe-347-improper-verification-of-cr-3227f29f #OffSeq #SAML #Ruby #Vuln
-
Has anyone done some kind of SSO / SAML auth thing which supports "N of M" type authentication?
Like, I want to log into a shared Fedi account to post something; I log into my SSO provider as usual, and another member of the same group needs to "approve" before I get a login ticket for the target account.
The intended market for this would be organisations who don't want to share a password for an account, or who want some oversight on how it's used.
-
I wrote a new blog post about PassBeyond, a lightweight SAML SP + reverse proxy to add SSO to self-hosted apps that don’t support modern authentication. It handles SAML, creates JWT sessions, and forwards identity via headers - no code changes needed.
🔗 https://blog.bella.network/securing-web-applications-with-passbeyond/