Not sure if I should send this under the radar but here's a blog post that claims there's a vulnerability in some OpenSAML code on the wiki: http://blog.sendsafely.com/post/69590974866/web-based-single-sign-on-and-the-dangers-of-saml Tom