OAuth2 and SAML(RFC 7522): When Your Assertion Needs a Passport
Note, We are exclusively talking about SAML2 in this story.
Read article: OAuth2 and SAML(RFC 7522): When Your Assertion Needs a Passport24 articles tagged SAML.
Note, We are exclusively talking about SAML2 in this story.
Read article: OAuth2 and SAML(RFC 7522): When Your Assertion Needs a PassportOne of the most fundamental questions in any identity or authorization system is how does the system know that the party presenting a credential is actually entitled to use it?
Read article: Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an IdentityIdentity engineers have a complicated relationship with SAML.
Read article: The OAuth2/OIDC Debugger Has Learned a New Trick: SAML2 Support Is HereThis blog post expands on delegation and related concepts introduced in my Kerberos Delegation blog post. It also brings together two blog series I’ve been working on over the years: SAML2 vs. JWT Series and Kerberos and Windows Security Series. Delegation is a critical building block of end-to-end…
Read article: Delegation — A General DiscussionI’ve written blog posts on the following identity protocols. I’m creating this post to have a central place to refer to “identity protocols”. I will periodically update this list as I publish new posts with related material.
Read article: The Common Identity ProtocolsRed Hat SSO v7.1 provides support for OAuth2, OpenID Connect, and SAML2. There are numerous other identity protocols, but these are quite common and can handle a wide variety of use cases.
Read article: Red Hat SSO v7.1 Spec SupportThere are several identity protocols that are commonly supported by Identity Providers today — OAuth2, OAuth2 Token Exchange, OIDC, SAML2 Browser Profile, WS-Trust, WS-Federation, etc. The OAuth2 and OIDC protocols are relative newcomers. The other protocols have been around longer — and, tend to…
Read article: Understanding WS-Federation — Passive Requestor ProfileThis post concludes our discussion of SAML2 and JWT. Here we look at a comparison of the features and use cases of the two technologies. It’s difficult to make a direct comparison of JWT and SAML2. As we’ve seen through this series, one must take into account the specifications that work in…
Read article: SAML2 vs JWT: A ComparisonThis post explores the equivalent JWT use cases corresponding to the five SAML2 use cases that were explored earlier in this series. We had to build up our tool set to get to this point — including exploring JWT, OAuth2, OpenID Connect, and the supporting specs. To be ready for this moment, we’ve…
Read article: JWT Use CasesThe following blog posts discuss SAML2 use cases that have been explored in this series:
Read article: SAML2 Use Cases