
How SAML works, and why XML signature wrapping keeps breaking it
How SAML works: the identity provider signs an XML assertion and hides the signature inside it. That is why XML signature wrapping bugs keep coming back.
Tag archive

How SAML works: the identity provider signs an XML assertion and hides the signature inside it. That is why XML signature wrapping bugs keep coming back.
Enterprise SSO is a federation of trust, not one shared login session. SAML or OIDC carries identity proof, while each application still owns its session and authorization.
Add CAS single sign-on to a Vert.x Web application with pac4j: session handler, CasClient, a SecurityHandler on a route, callback and logout handlers.

Releasing a Terraform module for an ephemeral, SSO-secured AWS Client VPN Today I'm...
OpsFusion now supports Enterprise Single Sign-On: teams can sign in through their own identity...
Health data must stay in its region, authentication must work everywhere. The selective residency pattern behind a 25M+ user multi-region SSO, with fallback.

What I learned wiring several apps to one Zitadel and brokering out to a customer's Keycloak: two very different APIs, a PKCE toggle that does nothing, and a logout that cannot federate.

Conclusion ELN ID is an in-house project run by EarthLink Network as a company, developed...
A short, reproducible guide to wiring ArgoCD login to AWS Identity Center using ArgoCD's bundled Dex...

If you juggle a lot of AWS accounts through IAM Identity Center, you know the ritual. You sit down,...
Stop Building Multi-Tenant Auth from Scratch. Use This Instead. Building a B2B SaaS application...

The modern cloud ecosystem relies heavily on the concept of "trust." When we store our most sensitive...