SAML
SAML
(Security Assertion Markup Language,
"turvadeklaratsioonide märgistuskeel")
olemus
XML-põhine autentimis-, loastus- ja salgamatusteabe vahetuse karkass, näiteks ainulogimisega pöördumiseks
= XML-based framework for exchange of authentication, authorization and non-repudiation information
ülevaateid
https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language
https://developers.onelogin.com/saml
https://blog.surf.nl/en/saml-for-dummies/
standard
https://wiki.oasis-open.org/security/FrontPage
turvalisus
https://www.owasp.org/index.php/SAML_Security_Cheat_Sheet
https://blog.netspi.com/attacking-sso-common-saml-vulnerabilities-ways-find/
https://www.okta.com/blog/2018/02/what-you-need-to-know-about-saml-vulnerability-research/
https://www.usenix.org/system/files/conference/usenixsecurity12/sec12-final91.pdf