sign and/or encrypt SAML assetions, hack MITM
Alan Buxey
alan.buxey at myunidays.com
Thu Feb 22 10:58:28 UTC 2024
hi,
> finnaly it is safe not to encrypt SAML assertions as long a signatures are
> well verified ?
>
>
signing is meant to ensure that the assertions have not been tampered with
- that only works if the SP is actually doing the required checking of the
signature....if it isn't then signing will not protect from your observed
MITM attacks. However as for 'safe' , well, that will depend on what is
being asserted - as if there is no encryption of the assertion then, whilst
they cannot tamper with the assertion, a malevolent actor can still read
the assertions and therefore collect potentially private information, PII,
group/project/access information etc
regards
alan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240222/e65fb07e/attachment.htm>
More information about the users
mailing list