Is Shibboleth SP susceptible to Golden Saml Attack
Tom Scavo
trscavo at gmail.com
Sun Dec 3 16:04:09 EST 2017
On Sun, Dec 3, 2017 at 1:40 PM, Amit Thukral <amit.thukral403 at gmail.com> wrote:
>
> I would like to know if Shibboleth SP is susceptible to "Golden Saml Attack"?
The "golden SAML attack" is a hoax. It has nothing to do with SAML.
Basically the "attack" says: If you possess an entity's signing key,
you can impersonate the entity at will. <duh>
> Is there any way we can prevent this ?
If you are an IdP, protect your SAML signing key at all costs. If you
are an SP, only accept assertions from trusted IdPs.
Tom
[1] https://www.cyberark.com/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-cloud-apps/
More information about the dev
mailing list