sign and/or encrypt SAML assetions, hack MITM

Morgan, Andrew J morgan at oregonstate.edu
Wed Feb 21 20:34:55 UTC 2024


The vendor should use well-known SAML SP software.  Don't trust anyone to write their own SAML SP.  Unfortunately, I have no idea what SP software to recommend for them except the Shibboleth SP.

Andy
________________________________
From: users <users-bounces at shibboleth.net> on behalf of jehan.procaccia at tem-tsp.eu <jehan.procaccia at tem-tsp.eu>
Sent: Wednesday, February 21, 2024 12:07 PM
To: users at shibboleth.net <users at shibboleth.net>
Subject: Re: sign and/or encrypt SAML assetions, hack MITM

[This email originated from outside of OSU. Use caution with links and attachments.]

On 21/02/2024 16:57, Peter Schober via users wrote:
> Morgan, Andrew J via users <users at shibboleth.net> [2024-02-21 16:20 CET]:
>> If you are able to modify the assertion without the SP rejecting it,
>> then that SP is not validating the signature.  Personally, I would
>> not use SAML with an SP that does not validate the signature.  As
>> you have found, anyone can modify the assertion to impersonate
>> another user - critical security bug.  Have you reported this issue
>> to the vendor's security contact?
Yes Morgan, we have reported the flow to the vendor, and are activelly
working on a correction . That's why I search for best-practice Doc  on
how to instruct them to do the right thinks, any pointer to that will be
greatly appreciated .
> Testing for this on a larger scale isn't trivial (and might include
> legal aspects) but an activity within GÉANT has recently started to
> look into this:
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.geant.org%2Fdisplay%2FGWP5%2FScalable%2Btesting%2Bfor%2Binsecure%2BSAML%2Bsignature%2Bvalidation&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344213736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=mKjesR%2By6vFQOt9Y3WxP6hyg%2B4Y8jPwRj%2BdHyWInpT4%3D&reserved=0<https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation>
>
Thanks again Peter for that link, it describe my problem, even more , it
focuses on properly validate the signature.

in my case it is worst, there is no signature check at all, I'll care
about the authenticity of the signature in the second step .

regards , jehan .

>
> -peter
--
For Consortium Member technical support, see https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344221440%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=55ew17NywXC2egkjJynEDz%2BMlj027NXNPeJwrzJgZc0%3D&reserved=0<https://shibboleth.atlassian.net/wiki/x/ZYEpPw>
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240221/a266e8ab/attachment.htm>


More information about the users mailing list