top | item 22740395

(no title)

someone13 | 6 years ago

This is part of what makes this class of bug so bad; it's not something you can "fix" at the IDP without doing exactly this. The issue occurs when a Service Provider (SP) is misconfigured, and in many cases the IDP doesn't actually get any sort of feedback that would let them detect the issue.

discuss

order

mc32|6 years ago

Is there a way to audit that kind of misconfiguration?

tptacek|6 years ago

Yes, tediously, with auditors who understand SAML and the (very informal) literature on SAML attacks. Hence, the concern.