Remix.run Logo
koolba a day ago

The root problem with SAML is there’s a million and one permutations to do the same thing.

Signed assertions. Signed messages. Encrypted messages. Encrypted assertions. Sign after normalization. Sign before normalization. Encrypt then sign. Sign then encrypt.

There’s too many ways to do too many things.

pseudohadamard 20 hours ago | parent [-]

That's because its built in part on XMLDSig, a genius idea to sign active content that can redefine its own semantics as it's being signed/verified. It's a triumph of ideology over common sense.

arethuza 19 hours ago | parent | next [-]

I think I got to the canonicalization part of the relevant spec and decided that life was too short...

NB I can absolutely see why canonicalization is required... just that it was the bit where I lost interest

pseudohadamard 16 hours ago | parent [-]

The first book that came out on XMLDSig, "Secure XML: The New Syntax for Signatures and Encryption", written by the chair of the working group, spent over half of its 500 pages wrestling with canonicalization, and even then it read more as a 250-page problem statement than a solution.

And that was before you got into deliberately malicious content that actively subverts the signature process.

19 hours ago | parent | prev [-]
[deleted]