<html><head><meta http-equiv="Content-Type" content="text/html charset=utf-8"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class="">On Aug 23, 2016, at 12:43 PM, Reynolds, Jeffrey <<a href="mailto:JReynolds@utdallas.edu" class="">JReynolds@utdallas.edu</a>> wrote:<br class=""><div><blockquote type="cite" class=""><br class="Apple-interchange-newline"><div class=""><div style="margin: 0in 0in 0.0001pt; font-size: 12pt; font-family: Calibri; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><span style="font-size: 11pt;" class="">I’m wondering what the best practice is for SAML debugging in browser.  I see a lot of SAML browser extensions available, but I’m not sure if I’m comfortable using them considering that they could have access to sensitive data.  Is there any trusted SAML debuggers out there, or applications that anyone uses and feels comfortable using?<o:p class=""></o:p></span></div><br class="Apple-interchange-newline"></div></blockquote><br class=""></div><div>They won’t have any greater access to the data on the wire than the browser does. If you encrypting data, then its still encrypted when you view it in the SAML debugger. I’ve had very few times when I personally needed to see the actual data values in the SAML Response for trouble shooting. It’s more about the protocol flow and whether specific attributes get released.</div><div><br class=""></div><div>Paul</div><div><br class=""></div><br class=""><div class="">
<div class="">Paul Hethmon</div><div class="">Chief Software Architect</div><div class=""><a href="mailto:paul.hethmon@clareitysecurity.com" class="">paul.hethmon@clareitysecurity.com</a></div><div class="">865.250.3517</div>

</div>
<br class=""></body></html>