Is Shibboleth SP susceptible to Golden Saml Attack

Tom Scavo trscavo at gmail.com
Sun Dec 3 16:04:09 EST 2017


On Sun, Dec 3, 2017 at 1:40 PM, Amit Thukral <amit.thukral403 at gmail.com> wrote:
>
> I would like to know if Shibboleth SP is susceptible to "Golden Saml Attack"?

The "golden SAML attack" is a hoax. It has nothing to do with SAML.
Basically the "attack" says: If you possess an entity's signing key,
you can impersonate the entity at will. <duh>

> Is there any way we can prevent this ?

If you are an IdP, protect your SAML signing key at all costs. If you
are an SP, only accept assertions from trusted IdPs.

Tom

[1] https://www.cyberark.com/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-cloud-apps/


More information about the dev mailing list