canada-ca / canada-ca/CATS-STAE

Should SAML authentication responses be signed?

Open
#10 0 comments 1 reaction 0 assignees View on GitHub
credential authentication identity authentication SAML
Dominant language
Shell
Stars
16
Forks
1
PR merge metrics
No merged PRs in 30d

Description

The Kantara interop profile now mandates the signing of SAML Response messages while making the signing of Assertions optional. This is the opposite of what the eGov 2.0 (and CATS 2.0) profiles required.

Is there any compelling reason why we should we move CATS in the same direction? Perhaps just for identity authentication?

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points. Start by reviewing the CATS authentication profile and comparing its current SAML Response and Assertion signing requirements with the Kantara, eGov 2.0, and CATS 2.0 profiles. Done means reaching and documenting a project decision on whether the signing requirements should change.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.