canada-ca / canada-ca/CATS-STAE
Should SAML authentication responses be signed?
- Dominant language
- Shell
- Stars
- 16
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
The Kantara interop profile now mandates the signing of SAML Response messages while making the signing of Assertions optional. This is the opposite of what the eGov 2.0 (and CATS 2.0) profiles required.
Is there any compelling reason why we should we move CATS in the same direction? Perhaps just for identity authentication?
Contributor guide
Research direction
The issue names no files, tests, or entry points. Start by reviewing the CATS authentication profile and comparing its current SAML Response and Assertion signing requirements with the Kantara, eGov 2.0, and CATS 2.0 profiles. Done means reaching and documenting a project decision on whether the signing requirements should change.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100