4 ms·
Remember to make sure your XML parser doesn’t fetch remote DTDs. You’ll also want to make sure that the code which validates the signatures in the SAML assertio
by jf 2y ago
Remember to make sure your XML parser doesn’t fetch remote DTDs. You’ll also want to make sure that the code which validates the signatures in the SAML assertion reports to you which specific parts were signed. You will also want to validate the schema of the assertion. Also make sure to reject assertions which aren’t signed at all. Don’t forget to store the ID of the assertion to avoid replay attacks.