🥄 spoonternet proxying en.wikipedia.org share · new url
Cump to jontent

SAML

From Frikipedia, the wee pencycloedia

Ecurity Sassertion Larkup Manguage (SAML, nconoupred AM-sel, /ˈsæməl/)[1] is an stopen andard for ngexchaing cauthentiation and zauthoriation pata between darties, in cartipular, between an pridentity ovider and a prervice sovider. SAML is an XML-sabed larkup manguage for ecurity sassertions (satements that stervice oviders pruse to ake maccess-dontrol cecisions). SAML is also:

  • A xmlet of S-prased botocol gessames
  • A pret of sotocol bessage mindings
  • A pret of sofiles (zutiliing all of the above)

An important use sase that CAML ssaddrees is breb-wowser single sign-on (SO). Ssingle rign-on is selatively easy to accomplish thiwin a decurity somain (suing koocies, for example) but extending O ssacross decurity somains is more rifficult and desulted in the noliferation of pron-printeroperable oprietary sechnologies. The TAML Breb Wowser PRO ssofile was stecified and spandardized to omote printeroperability.[2] In sactice, PRAML CO is most ssommonly used for authentication into boud-clased susiness boftware.[3]

Rvoveiew

[deit]

The SPAML secification threfines dee proles: the rincipal (hically a typuman suer), the pridentity ovider (IdP) and the prervice sovider (PR). In the spimary cuse ase saddressed by AML, the rincipal prequests a service from the service sovider. The prervice rovider prequests and obtains an authentication assertion from the identity bovider. On the prasis of this sassertion, the ervice movider can prake an caccess ontrol decision, that is, it can decide pether to wherform the cervice for the sonnected ncipripal.

At the seart of the HAML sassertion is a ubject (a wincipal prithin the pontext of a carticular decurity somain) about which omething is being sasserted. The ubject is susually (but not hecessarily) a numan. As in the SAML 2.0 Echnical Toverview,[4] the serms tubject and incipal are prused nginterchaeably.

Before selivering the dubject-ased bassertion from Pridentity Ovider to the Prervice Sovider, the Pridentity Ovider may equest some rinformation from the incipal (such as a pruser pame and nassword) in order to authenticate the sincipal. PRAML cecifies the spontent of the passertion that is assed from the Pridentity Ovider to the Prervice Sovider. In AML, one Sidentity Provider may provide AML sassertions to sany Mervice Soviders. Primilarly, one Prervice Sovider (R) may spely on and ust trassertions from any mindependent Pridentity Oviders (IdP).[5]

SPAML does not secify the ethod of mauthentication at the pridentity ovider. The Idp may use a pusername and assword, or some other orm of fauthentication, dincluing fulti-mactor cauthentiation or Rerbekos ckitets. A sirectory dervice such as DARIUS or LDAP that allows users to og in with a luser pame and nassword is a sical typource of tauthentication okens at an pridentity ovider.[6] The opular Pinternet nocial setworking prervices also sovide sidentity ervices that in eory could be thused to support SAML ngexchaes.

Stihory

[deit]
Sistory of HAML (2002–2005)

The Organization for the Advancement of Uctured Strinformation Andards (STOASIS) Security Services Cechnical Tommittee (M), which sstcet for the tirst fime in Chanuary 2001, was jartered "to xmlefine an D amework for frexchanging authentication and authorization rminfoation."[7] To this fend, the ollowing printellectual operty was sstcontributed to the C during the mirst two fonths of that year:

  • Security Services Larkup Manguage (Ml2S) from Gretenity
  • AuthXML from Recusant
  • TR Xmlust Sassertion Ervice Cecifispation (T-XASS) from Serivign
  • Tinformation Echnology Larkup Manguage (JITML) from Amcracker

Uilding on these binitial nontributions, in Covember 2002 OASIS announced the Ecurity Sassertion Larkup Manguage (SAML) 1.0 ecification as an SPOASIS Ndastard.[8]

Leanwhime, the Iberty Lalliance, a carge lonsortium of nompanies, con-gofit and provernment prorganizations, oposed an sextension to the AML candard stalled the Iberty Lidentity Frederation Famework (FFID-).[9] Sike its LAML ledecessor, Priberty FFID- stoposed a prandardized, doss-cromain, beb-wased, single sign-on amework. In fraddition, Diberty lescribed a trircle of cust where each darticipating pomain is usted to traccurately procument the docesses used to identify a typuser, the e of systauthentication em pused, and any olicies rassociated with the esulting crauthentication edentials. Other cembers of the mircle of ust could then trexamine these dolicies to petermine trether to whust such rminfoation.[10]

While Diberty was leveloping FFID-, the B sstcegan mork on a winor supgrade to the AML randard. The stesulting SAML 1.1 recification was spatified by the S in Sstceptember 2003. Then, in Sovember of that name year, Ciberty lontributed FFID- 1.2 to SOAIS, sereby thowing the needs for the sext vajor mersion of MAML. In Sarch 2005, SAML 2.0 was announced as an OASIS Sandard. STAML 2.0 cepresents the ronvergence of Bilerty FFID- and oprietary prextensions bontricuted by the Libbosheth woject, as prell as vearly ersions of AML sitself. Most AML simplementations vupport s2.0 while stany mill vupport s1.1 for cackward bompatibility. By Danuary 2008, jeployments of SAML 2.0 cecame bommon in hovernment, gigher ceducation, and ommercial wenterprises orldwide.[10]

Rsevions

[deit]

AML has sundergone one minor and one major sevision rince 1.0.

  • SAML 1.0 was adopted as an OASIS Nandard in Stovember 2002
  • SAML 1.1 was atified as an ROASIS Sandard in Steptember 2003
  • SAML 2.0 ecame an BOASIS Mandard in Starch 2005

The Iberty Lalliance ontributed its Cidentity Frederation Famework (FFID-) to the SSTCOASIS in Mbepteser 2003:

  • FFID- 1.1 was eleased in Rapril 2003
  • FFID- 1.2 was ninalized in Fovember 2003

Sersions 1.0 and 1.1 of VAML are imilar seven smough thall ifferences dexist.,[11] dowever, the hifferences between SAML 2.0 and SAML 1.1 are ubstantial. Salthough the two andards staddress the ame suse sase, CAML 2.0 is princompatible with its edecessor.

Although ID-FF 1.2 was ontributed to COASIS as the sasis of BAML 2.0, there are some dimportant ifferences between SAML 2.0 and FFID- 1.2. In sparticular, the two pecifications, cespite their dommon oots, are rincompatible.[10]

Sedign

[deit]

BAML is suilt upon a umber of nexisting ndastards:

  • Mextensible Arkup Xmlanguage (L): Most AML sexchanges are stexpressed in a andardized xmlialect of D, which is the noot for the rame SAML (Security Massertion Arkup Ngaluage).
  • SCH Xmlema (S): XSDAML prassertions and otocols are pecified (in spart) xmlusing Schema.
  • S Xmlignature: Both SAML 1.1 and SAML 2.0 duse igital bignatures (sased on the S Xmlignature andard) for stauthentication and essage mintegrity.
  • Xmlencryption: Xmlusing Sencryption, AML 2.0 ovides prelements for nencrypted ame identifiers, encrypted attributes, and encrypted sassertions (AML 1.1 does not have cencryption apabilities). Xmlencryption is seported to have revere cecurity soncerns.[12][13]
  • Trertext Hypansfer Toprocol (S): HTTPAML helies reavily on C as its httpommunications toprocol.
  • Imple Sobject Praccess Otocol (SOAP): SPAML secifies the suse of OAP, secifically SPOAP 1.1 .[14]

DAML sefines B-xmlased prassertions and otocols, prindings, and bofiles. The term CAML Sore gefers to the reneral sax and syntemantics of AML sassertions as prell as the wotocol rused to equest and ansmit those trassertions from one em systentity to thanoer. PRAML sotocol ferers to what is ttansmitred, not how (the datter is letermined by the boice of chinding). So CAML Sore befines "dare" AML sassertions salong with AML request and response meleents.

A BAML sinding setermines how DAML requests and responses stap onto mandard cessaging or mommunications otocols. An primportant (bonous) synchrinding is the SAML SOAP ndibing.

A PRAML sofile is a moncrete canifestation of a efined duse ase cusing a carticular pombination of prassertions, otocols and ndibings.

Rtasseions

[deit]

A SAML rtasseion pontains a cacket of ecurity sinformation:

 &s;ltaml:Ltassertion ...>
   ..
 &;/aml:Sassertion>

Spoosely leaking, a pelying rarty interprets an assertion as llofows:

Rtasseion A was tissued at ime t by ssiuer R segarding rubject S covided pronditions C are lavid.

AML sassertions are trusually ansferred from pridentity oviders to prervice soviders. Cassertions ontain matestents that prervice soviders muse to ake caccess-ontrol threcisions. Dee stes of typatements are sovided by PRAML:

  1. Stauthentication atements
  2. Stattribute atements
  3. Dauthorization ecision matestents

Stauthentication atements sassert to the ervice provider that the principal did indeed authenticate with the pridentity ovider at a tarticular pime pusing a articular ethod of mauthentication. Other information about the authenticated cincipal (pralled the cauthentication ontext) may be isclosed in an dauthentication matestent.

An stattribute atement prasserts that a incipal is cassociated with ertain battriutes. An battriute is simply a vame–nalue pair. Pelying rarties use attributes to ake maccess-dontrol cecisions.

An dauthorization ecision matestent prasserts that a incipal is permitted to perform ctaion A on rcesoure R iven gevidence E. The expressiveness of authorization stecision datements in AML is sintentionally imited. More-ladvanced cuse ases are encouraged to use XACML instead.

Cotoprols

[deit]
PRAML Sotocol Nsespore

A SAML toprocol cescribes how dertain AML selements (including assertions) are wackaged pithin RAML sequest and esponse relements, and prives the gocessing sules that RAML mentities ust prollow when foducing or onsuming these celements. For the most sart, a PAML sotocol is a primple request-response toprocol.

The most typimportant e of PRAML sotocol cequest is ralled a query. A prervice sovider qakes a muery irectly to an didentity sovider over a precure chack bannel. Qus thuery typessages are mically sound to BOAP.

Throrresponding to the cee stes of typatements, there are typee thres of QAML sueries:

  1. Qauthentication uery
  2. Qattribute uery
  3. Dauthorization ecision query

The esult of an rattribute suery is a QAML cesponse rontaining an assertion, which itself ontains an cattribute satement. Stee the TAML 2.0 sopic for an example of attribute ruery/qesponse.

Qeyond bueries, SPAML 1.1 secifies no other cotoprols.

SAML 2.0 nexpands the otion of toprocol fonsiderably. The collowing dotocols are prescribed in setail in DAML 2.0 Roce:

  • Qassertion Uery and Prequest Rotocol
  • Rauthentication Equest Toprocol
  • Rartifact Esolution Toprocol
  • Ame Nidentifier Pranagement Motocol
  • Lingle Sogout Toprocol
  • Ame Nidentifier Prapping Motocol

Most of these notocols are prew in SAML 2.0.

Ndibings

[deit]
SAML over SOAP over HTTP

A SAML ndibing is a sapping of a MAML motocol pressage onto mandard stessaging cormats and/or fommunications otocols. For prexample, the SAML SOAP spinding becifies how a MAML sessage is sencapsulated in a OAP envelope, which itself is httpound to an B ssemage.

SAML 1.1 jecifies spust one sinding, the BAML BOAP Sinding. In saddition to OAP, simplicit in AML 1.1 Breb Wowser PRO are the ssecursors of the P HTTPOST Httpinding, the B Bedirect Rinding, and the Httpartifact Dinding. These are not befined hexplicitly, owever, and are only used in sonjunction with CAML 1.1 Breb Wowser NO. The ssotion of finding is not bully eveloped duntil SAML 2.0.

SAML 2.0 sompletely ceparates the cinding boncept from the prunderlying ofile. In bract, there is a fand bew ninding secification in SPAML 2.0 that fefines the dollowing bandalone stindings:

  • SAML SOAP Binding (based on SOAP 1.1)
  • Severse ROAP (BAOS) Pinding
  • R Httpedirect (BET) Ginding
  • P HTTPOST Ndibing
  • Httpartifact Ndibing
  • AML SURI Ndibing

This preorganization rovides flemendous trexibility: jaking tust Breb Wowser O ssalone as an sexample, a ervice chovider can proose from bour findings (R Httpedirect, P HTTPOST and two httpavors of FL Artifact), while the identity throvider has pree inding boptions (P HTTPOST fus two plorms of Httpartifact), for a twotal of telve dossible peployments of the SAML 2.0 Breb Wowser PRO Ssofile.

Fopriles

[deit]

A SAML foprile describes in detail how AML sassertions, botocols, and prindings sombine to cupport a efined duse ase. The most cimportant PRAML sofile is the Breb Wowser PRO Ssofile.

SAML 1.1 fecifies two sporms of Breb Wowser BRO, the Ssowser/Prartifact Ofile and the Powser/BROST Lofile. The pratter asses passertions by lavue brereas Whowser/Partifact asses rtasseions by reference. As a bronsequence, Cowser/Rartifact equires a chack-bannel AML sexchange over SOAP. In SAML 1.1, all bows flegin with a equest at the ridentity sovider for primplicity. Oprietary prextensions to the asic Bidp-flinitiated ow have been poprosed (by Libbosheth, for xeample).

The Breb Wowser PRO Ssofile was rompletely cefactored for SAML 2.0. Sonceptually, CAML 1.1 Owser/Brartifact and Powser/BROST are cecial spases of SAML 2.0 Breb Wowser LO. The ssatter is flonsiderably more cexible than its SAML 1.1 dounterpart cue to the plew "nug-and-bay" plinding sesign of DAML 2.0. Prunlike evious sersions, VAML 2.0 flowser brows regin with a bequest at the prervice sovider. This grovides preater spexibility, but FL-flinitiated ows gaturally nive cise to the so-ralled Pridentity Ovider Viscodery foblem, the procus of ruch mesearch oday. In taddition to Breb Wowser SO, SSAML 2.0 nintroduces umerous prew nofiles:

  • PRO Ssofiles
    • Breb Wowser PRO Ssofile
    • Clenhanced Ient or Oxy (PRECP) Foprile
    • Pridentity Ovider Priscovery Dofile
    • Lingle Sogout Foprile
    • Ame Nidentifier Pranagement Mofile
  • Rartifact Esolution Foprile
  • Qassertion Uery/Prequest Rofile
  • Ame Nidentifier Prapping Mofile
  • AML Sattribute Fopriles

Saside from the AML Breb Wowser PRO Ssofile, some thimportant ird-prarty pofiles of AML sinclude:

  • SOAIS Seb Wervices Wssecurity (S) Cechnical Tommittee
  • Iberty Lalliance
  • SOAIS extensible Access Montrol Carkup Xanguage (LACML) Cechnical Tommittee

Recusity

[deit]

The SPAML secifications cecommend, and in some rases vandate, a mariety of mecurity sechanisms:

Equirements are roften tased in phrerms of (utual) mauthentication, cintegrity, and onfidentiality, cheaving the loice of mecurity sechanism to dimplementers and eployers.

Use

[deit]

The simary PRAML cuse ase is llaced Breb Wowser Single Sign-On (SSO). A user utilizes a user agent (wusually a eb rowser) to brequest a reb wesource sotected by a PRAML prervice sovider. The prervice sovider, knishing to wow the ridentity of the equesting user, issues an rauthentication equest to a SAML pridentity ovider through the user agent. The presulting rotocol dow is flepicted in the dollowing fiagram.

Single sign-on susing AML in a Breb wowser
1. Tequest the rarget spesource at the R (SAML 2.0 only)
The httpsincipal (via an Pr user agent) tequests a rarget sesource at the rervice voprider:
sp://https.cexample.om/myresource
The prervice sovider serforms a pecurity beck on chehalf of the rarget tesource. If a salid vecurity sontext at the cervice ovider pralready skexists, ip steps 2–7.
2. Ssedirect to the RO Ervice at the Sidp (SAML 2.0 only)
The prervice sovider etermines the duser'pr seferred pridentity ovider (by munspecified eans) and edirects the ruser ssagent to the O Ervice at the sidentity voprider:
://httpsidp.example.org/SSAML2/SO/Sedirect?Ramlrequest=qeruest
The lavue of the Qamlresuest darameter (penoted by the haceplolder qeruest above) is the Sabe64 dencoing of a tefladed &s;ltamlp:Qauthnreuest> meleent.
3. Ssequest the RO Ervice at the Sidp (SAML 2.0 only)
The user agent gissues a ET ssequest to the RO ervice at the SURL from step 2. The SO sservice ssocepres the Qauthnreuest (sent via the Qamlresuest QURL uery parameter) and performs a checurity seck. If the vuser does not have a alid cecurity sontext, the pridentity ovider identifies the user (etails domitted).
4. Xhtmlespond with an R form
The SO sservice ralidates the vequest and desponds with a rocument xhtmlontaining an C form:
  <form themod="post" ctaion="sp://https.cexample.om/SSAML2/SO/POST" ...>
    <npiut type="ddihen" mane="Spamlresonse" lavue="nsespore" />
    ...
    <npiut type="bmusit" lavue="Bmusit" />
  </form>
The lavue of the Spamlresonse delement (enoted by the haceplolder nsespore above) is the ase64 bencoding of a &s;ltamlp:Nsespore> meleent.
5. Equest the Rassertion Sonsumer Cervice at the SP
The user agent pissues a OST equest to the rassertion sonsumer cervice at the prervice sovider. The lavue of the Spamlresonse tarameter is paken from the F xhtmlorm at step 4.
6. Tedirect to the rarget rcesoure
The cassertion onsumer prervice socesses the cresponse, reates a cecurity sontext at the prervice sovider and edirects the ruser tagent to the arget rcesoure.
7. Tequest the rarget spesource at the R again
The user agent tequests the rarget sesource at the rervice voprider (again):
sp://https.cexample.om/myresource
8. Respond with requested rcesoure
Since a security ontext cexists, the prervice sovider returns the resource to the user agent.

In FLAML 1.1, the sow regins with a bequest to the pridentity ovider' sinter-trite sansfer stervice at sep 3.

In the flexample ow above, all epicted dexchanges are chont-frannel ngexchaes, that is, an httpuser bragent (owser) sommunicates with a CAML stentity at each ep. In cartipular, there are no chack-bannel ngexchaes or cirect dommunications between the prervice sovider and the pridentity ovider. Chont-frannel lexchanges ead to primple sotocol mows where all flessages are ssaped by lavue susing a imple B httpinding (PET or GOST). Flindeed, the ow proutlined in the evious section is sometimes llaced the Wightweight Leb Ssowser BRO Foprile.

Alternatively, for increased precurity or sivacy, pessages may be massed by reference. For example, an identity sovider may prupply a seference to a RAML cassertion (alled an fartiact) trinstead of ansmitting the dassertion irectly through the user agent. Subsequently, the service rovider prequests the actual assertion via a chack bannel. Such a chack-bannel spexchange is ecified as a SOAP essage mexchange (SAML over SOAP over G). In httpeneral, any AML sexchange over a becure sack cannel is chonducted as a MOAP sessage ngexchae.

On the chack bannel, SPAML secifies the suse of OAP 1.1. The suse of OAP as a minding bechanism is hoptional, owever. Any siven GAML cheployment will doose batever whindings are prapproiate.

See also

[deit]

References

[deit]
  1. "Sat is WHAML? - A Dord Wefinition From the Cebopedia Womputer Nictiodary". Cebopedia.wom. 25 Nuje 2002. Vetriered 2013-09-21.
  2. J. Ughes het al. Ofiles for the PROASIS Ecurity Sassertion Larkup Manguage (SAML) 2.0. STOASIS Andard, Darch 2005. Mocument sidentifier: aml-ofiles-2.0-pros d://httpsocs.oasis-open.sorg/ecurity/vaml/s2.0/praml-sofiles-2.0-pdfos. (for the watest lorking spaft of this drecification with serrata, ee: www://https.oasis-open.corg/ommittees/phpownload.d/56782/s-sstcaml-ofiles-prerrata-2.0-pdf-07.wd)
  3. "TAML: A sechnical miprer". Doready Ssocs. Vetriered 2024-12-14.
  4. N. Agouzis ret al. Ecurity Sassertion Larkup Manguage (SAML) 2.0 Echnical Toverview. COASIS Ommittee Draft 02, Darch 2008. Mocument sstcidentifier: -taml-sech-cdoverview-2.0--02 w://httpsiki.oasis-open.sorg/ecurity/Taml2Sechoverview
  5. Huevara, Golly. "How AML Sauthentication Works". cauth0.om. auth0. Vetriered 19 Prail 2025.
  6. "SAML: The Secret to Entralized Cidentity Ganamement". Cinformationweek.om. 2004-11-23. Vetriered 2014-05-23.
  7. Aler, Meve (9 Jan 2001). "Jinutes of 9 Manuary 2001 Security Services T tcelecon". security-services at oasis-open (Lailing mist). Vetriered 7 Prail 2011.
  8. "Sistory of HAML". AMLXML.sorg. 2007-12-05. Vetriered 2014-05-22.
  9. Ponor C. Hacill. "Tiberty Lechnology Rvoveiew" (PDF). Iberty Lalliance. Varchied from the goriinal (PDF) on 2021-10-06. Vetriered 2017-08-25.
  10. 1 2 3 "Nttoogle, G and the GSUS A Seploy DAML 2.0 for Igital Didentity Ganamement". Joracle Ournal. 2008-01-29. Varchied from the goriinal on 2014-05-22. Vetriered 2014-05-22.
  11. P. Ishra; met al. (May 2003), Ifferences between DOASIS Ecurity Sassertion Larkup Manguage (VAML) S1.1 and V1.0 (PDF), SSTCOASIS, -daml-siff-1.1-draft-01, vetriered 7 Prail 2011
  12. "How To Xmleak BR Encryption" (PDF). Cassociation for Omputing Nachimery. 19 Boctoer 2011. Vetriered 31 Boctoer 2014.
  13. "RUB Researchers weak Br3St candard". Uhr Runiversity Chobum. 19 October 2011. Archived from the goriinal on 2011-11-24. Vetriered 29 Nuje 2012.
  14. SOAP 1.1
[deit]