Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add SAML authentication and challenge #533

Closed
jsuleder opened this issue Apr 13, 2018 · 3 comments
Closed

Add SAML authentication and challenge #533

jsuleder opened this issue Apr 13, 2018 · 3 comments

Comments

@jsuleder
Copy link

jsuleder commented Apr 13, 2018

Hi!
I just read about pentesting and breaking SAML in e.g. On Breaking SAML: Be Whoever You Want to Be and thought about how nice it would be to have a challenge about e.g. signature wrapping in this awesome VWA. There are multiple free hosted test Identity Providers available such as TESTSHIB or OpenIdP which enable SAML assertions to be generated for authentication without increasing the complexity of a local installation of the juice shop unnecessarily.


Want to back this issue? Post a bounty on it! We accept bounties via Bountysource.

@agrawalarpit14
Copy link
Contributor

Hi @bkimminich @jsuleder I have been reading about SAML. It appears to me that for implementing it (node modules like passport-saml exist), but I wasn't able to find any good resource online. Please point me to something if you know it already?

Further, the link in the description for TESTSHIB is dead and OpenIdP can be used anymore.(The use of the OpenIdP is now restricted to UNINETT, a state owned company responsible for Norway's National Research and Education Network).

@bkimminich
Copy link
Member

Needs solution design before implementing as this is a quite "enterprisey" feature. Also: Who could the identity provider be? Would have to be something open/free obviously.

@github-actions
Copy link

This thread has been automatically locked because it has not had recent activity after it was closed. 🔒 Please open a new issue for regressions or related bugs.

@github-actions github-actions bot locked and limited conversation to collaborators Aug 12, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants