← dev

Identity Management

Vocabulary

Provisioning

How we keep in sync the user profiles information between Idp and SP

We can do it:


SAML (Security Assertion Markup Language)

Vocabulary

Let's say I want to login to A Cloud Guru.

Implementation

SAML Request

This will be stringified, encoded and passed in the query string to the IdP once the SP redirects there

<samlp:AuthnRequest ID="" IssueInstant="" Destination="" AssertionConsumerServiceURL="">
    <saml:Issuer> </saml:Issuer>
</samlp:AuthnRequest>

This xml is heavily minimized, there's a ton of information missing

SAML Response

This is sent to the SP AssertionConsumerServiceURL once the user has authenticated

<saml2p:Response ID="" InResponseTo="" Destination="">
    <saml:Issuer> </saml:Issuer>
    <saml2:Assertion>
        <ds:Signature> </ds:Signature>
        <saml2:Subject> 
            <saml2:NameID> </saml2:NameID>
        </saml2:Subject>
        <saml2:Conditions NotBefore="" NotOnOrAfter=""> </saml2:Conditions>
        <saml2:AttributeStatement> 
            <saml2:Attribute> </saml2:Attribute>
        </saml2:AttributeStatement>
    </saml2:Assertion>
</saml2p:Response>

This xml is heavily minimized, there's a ton of information missing

For both Request and response:

Weak points & Best practices

It boils down to bad implementation, there is nothing inherently insecure with the protocol

Sources

SAML