SAML Encryption - PowerPoint PPT Presentation

1 / 5
About This Presentation
Title:

SAML Encryption

Description:

Scott's select technique. Assertion. Replace with EncryptedData (and optional EncryptedKey) ... Not Schema Valid (use Scott's technique) Encrypt Assertion Element ... – PowerPoint PPT presentation

Number of Views:73
Avg rating:3.0/5.0
Slides: 6
Provided by: halloc
Category:

less

Transcript and Presenter's Notes

Title: SAML Encryption


1
SAML Encryption
2
Functionality
  • Encrypt Assertion
  • Encrypt NameIdentifier (Schema valid)
  • Encrypt Attribute (Schema valid)
  • Excluded
  • Arbitrary encryption
  • Encrypted AttributeValue (w/o AttributeName)

3
Approach
  • NameIdentifier Attribute
  • Scotts select technique
  • Assertion
  • Replace with EncryptedData
  • (and optional EncryptedKey)

4
Order of Operations
  • Super-encryption allowed (use questionable)
  • Signed Assertion
  • Encrypted Assertion
  • Sign then encrypt
  • Encrypted NameIdentifier Attribute
  • Encrypt then sign
  • Signed Request or Response
  • Encrypt then sign

5
Issue - Assertion Encryption
  • Encrypt Assertion Content
  • Not Schema Valid (use Scotts technique)
  • Encrypt Assertion Element
  • Potentially two elements (data key)
  • In SOAP body violates WS-I BP
  • (Need wrapper)
  • Drop functionality?
Write a Comment
User Comments (0)
About PowerShow.com