5 ms·
Decoupled authentication from your application should be part of any base architecture these days. The article is thin on details, but adding SAML authenticati
by Steeeve 8y ago
Decoupled authentication from your application should be part of any base architecture these days.
The article is thin on details, but adding SAML authentication to the mix shouldn't be terribly difficult if you have somebody on board or bring somebody in who knows it already.
Learning how to do it without any experience is fraught with problems. The documentation is hard to absorb with all kinds of abstracted out concepts and important settings that are easy to overlook (like requiring encrypted assertions). And really, the more you dig into it the more complex it seems to be, when on the surface the concept is very simple. Unfortunately, that's one of the reasons that libraries supporting SAML aren't as widely available as they should be given it's age.
It's kind of like SOAP. If you know what you're doing and you've done it before, it's simple. If you're brand new to it, you're left twitching and angry at the end of a weekend coding session.
Regardless, decouple your authentication mechanisms and be prepared to add support for a new technology as necessary. Don't just think about end users, think about automation, how you might support it, and how it behaves differently.
- newscracker 8y agoI wouldn't suggest anyone to develop SAML support on their own unless they want to sell that as a component or service by itself. Instead, I'd strongly recommend that they look for libraries that have been around for sometime that take the grunt work out and provide high level APIs for the application to invoke. With this approach, supporting SAML becomes a whole lot easier and quicker to accomplish. One may have to pay real money though, depending on the platform, framework and language. Free ones in this area, to the extent of my research, come up short on reliability. Also, the most common use cases are related to browsers, and don't need the entire specification of SAML to be implemented, like all the profiles, for example.