<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<div dir="ltr">
<div dir="ltr">There is a PHP one (simpleSamlPHP) - it can also do IdP mode (no idea why you'd use that though).</div>
<div dir="ltr">Last time I tried to deploy it, to protect a PHP webapp I made, I couldn't find the latest version with the www folder it needed. So got the windows SP running with a handful of questions asked on here.<span></span></div>
<div id="ms-outlook-mobile-signature">
<div><br>
</div>
Sent from <a href="https://aka.ms/o0ukef">Outlook for iOS</a></div>
</div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Morgan, Andrew J via users <users@shibboleth.net><br>
<b>Sent:</b> Wednesday, February 21, 2024 8:34:55 PM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Morgan, Andrew J <morgan@oregonstate.edu><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack MITM</font>
<div> </div>
</div>
<style type="text/css" style="display:none">
<!--
p
{margin-top:0;
margin-bottom:0}
-->
</style>
<div dir="ltr">
<table border="0" cellspacing="0" cellpadding="0" align="left" width="100%">
<tbody>
<tr>
<td style="background:#ffb900; padding:5pt 2pt 5pt 2pt"></td>
<td width="100%" cellpadding="7px 6px 7px 15px" style="background:#fff8e5; padding:5pt 4pt 5pt 12pt; word-wrap:break-word">
<div style="color:#222222"><span style="color:#222; font-weight:bold">Caution:</span> Please take care when clicking on links or opening attachments in emails that originate from outside of the university. When in doubt, contact the ITS service desk.
</div>
</td>
</tr>
</tbody>
</table>
<br>
<div>
<div class="x_elementToProof" style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
The vendor should use well-known SAML SP software. Don't trust anyone to write their own SAML SP. Unfortunately, I have no idea what SP software to recommend for them except the Shibboleth SP.</div>
<div class="x_elementToProof" style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<div class="x_elementToProof" style="font-family:Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
Andy<br>
</div>
<div id="x_appendonsend"></div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="x_divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of jehan.procaccia@tem-tsp.eu <jehan.procaccia@tem-tsp.eu><br>
<b>Sent:</b> Wednesday, February 21, 2024 12:07 PM<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: sign and/or encrypt SAML assetions, hack MITM</font>
<div> </div>
</div>
<div class="x_BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="x_PlainText">[This email originated from outside of OSU. Use caution with links and attachments.]<br>
<br>
On 21/02/2024 16:57, Peter Schober via users wrote:<br>
> Morgan, Andrew J via users <users@shibboleth.net> [2024-02-21 16:20 CET]:<br>
>> If you are able to modify the assertion without the SP rejecting it,<br>
>> then that SP is not validating the signature. Personally, I would<br>
>> not use SAML with an SP that does not validate the signature. As<br>
>> you have found, anyone can modify the assertion to impersonate<br>
>> another user - critical security bug. Have you reported this issue<br>
>> to the vendor's security contact?<br>
Yes Morgan, we have reported the flow to the vendor, and are activelly<br>
working on a correction . That's why I search for best-practice Doc on<br>
how to instruct them to do the right thinks, any pointer to that will be<br>
greatly appreciated .<br>
> Testing for this on a larger scale isn't trivial (and might include<br>
> legal aspects) but an activity within GÉANT has recently started to<br>
> look into this:<br>
> <a href="https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation" originalsrc="https://wiki.geant.org/display/GWP5/Scalable+testing+for+insecure+SAML+signature+validation" shash="lWkD3Ng5Kch66FHHV2e9SOfiwVyDdemJbbPr2zex3/oQPpcfkbFhoAWkrGTIzQs0CxKhQgADkNzpTMLmZ+aYw1oPvFvxgpXK9yJMM4AYp4fFzZQvjSGDxfHThOXP8I/mNfMP9knWsxg2QPPxoC5l7ZQxD+v0tzx9VjpUSxnTCuw=">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwiki.geant.org%2Fdisplay%2FGWP5%2FScalable%2Btesting%2Bfor%2Binsecure%2BSAML%2Bsignature%2Bvalidation&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344213736%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=mKjesR%2By6vFQOt9Y3WxP6hyg%2B4Y8jPwRj%2BdHyWInpT4%3D&reserved=0</a><br>
><br>
Thanks again Peter for that link, it describe my problem, even more , it<br>
focuses on properly validate the signature.<br>
<br>
in my case it is worst, there is no signature check at all, I'll care<br>
about the authenticity of the signature in the second step .<br>
<br>
regards , jehan .<br>
<br>
><br>
> -peter<br>
--<br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" originalsrc="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" shash="gayOjNXgIB59hlC7kmKQdgyxjPxaDhbzcM/YRvgtVm4kivD/MroxjTDzDfD6TchjXW8+tlb1k4BRxCcW1Y3kCbtw9KeqykPrtr1TjL4/XAYuaYl1bOxJ/MMg1EfGUEKl8/sHt1LKtoE12Tr9PfZCHuuwYvXgaXoXmMSiJL3zRM4=">
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fshibboleth.atlassian.net%2Fwiki%2Fx%2FZYEpPw&data=05%7C02%7Cmorgan%40oregonstate.edu%7C03cb1f9bcf8a4ae3eb8008dc3318b10a%7Cce6d05e13c5e4d6287a84c4a2713c113%7C0%7C0%7C638441428344221440%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C0%7C%7C%7C&sdata=55ew17NywXC2egkjJynEDz%2BMlj027NXNPeJwrzJgZc0%3D&reserved=0</a><br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font></div>
</div>
</div>
</body>
</html>