| ▲ | koolba a day ago | ||||||||||||||||||||||
The root problem with SAML is there’s a million and one permutations to do the same thing. Signed assertions. Signed messages. Encrypted messages. Encrypted assertions. Sign after normalization. Sign before normalization. Encrypt then sign. Sign then encrypt. There’s too many ways to do too many things. | |||||||||||||||||||||||
| ▲ | pseudohadamard 20 hours ago | parent [-] | ||||||||||||||||||||||
That's because its built in part on XMLDSig, a genius idea to sign active content that can redefine its own semantics as it's being signed/verified. It's a triumph of ideology over common sense. | |||||||||||||||||||||||
| |||||||||||||||||||||||