skip to content

SAML

The XML standard behind enterprise SSO: signed assertions, IdP and SP roles, POST and Redirect bindings, and metadata trust. B2B integrations still arrive as SAML, so interviewers still ask.

part ofFederated identityoverview, primer and where to startread it →
on this pageshow

questions

page 2 of 2

When an identity provider authenticates its users against an upstream identity provider, which role does it play on each leg?

level: seniorimportance: nice to knowfreq 24%

basics

~20 s

It plays both. Toward the upstream party it is a service provider: it consumes and validates that assertion. Toward the downstream party it is an identity provider, issuing its own assertion under its own key and its own entityID.

open as a page

When an identity provider signs a SAML assertion and then encrypts it, what can the service provider prove that the reverse order cannot?

level: seniorimportance: nice to knowfreq 22%

basics

~20 s

Sign-then-encrypt puts the ds:Signature inside the ciphertext, so after decryption the service provider verifies a signature over the plaintext claims and can prove the issuer authored exactly those attributes. An outer signature over ciphertext proves only who assembled the message.

open as a page

showing 31–32 of 32