SAML-based products and services

Last updated

Security Assertion Markup Language (SAML) is a set of specifications that encompasses the XML-format for security tokens containing assertions to pass information about a user and protocols and profiles to implement authentication and authorization scenarios. This article has a focus on software and services in the category of identity management infrastructure, which enable building Web-SSO solutions using the SAML protocol in an interoperable fashion. Software and services that are only SAML-enabled do not go here.

Contents

Products that provide SAML actors

SAML actors are Identity Providers (IdP), Service Providers (SP), Discovery Services, ECP Clients, Metadata Services, or Broker/IdP-proxy. This table shows the capability of products according to Kantara Initiative testing. [1] [2] Claimed capabilities are in column "other". Each mark denotes that at least one interoperability test was passed. Detailed results with product and test procedure versions are available at the Kantara/Liberty site given below.

NOTE: This table represents a snapshot over time roll up of the most recent product test results (multiple testing rounds). Please note that some products features and abilities may have been updated since they were last tested. Please check the website information of the originating product for the latest features and updates.

Product NameProject/VendorLicenseKantara-certified InteroperabilityOther Features
IdP
IdP Light
SP
SP Light
eGov 1.5
Attr Auth Resp
POST Bind.
RolesProtocols
Broker
Discovery
ECP
IdP
IdP Proxy
Reverse Proxy
SP
10Duke Identity Provider [3] 10DukeCommercialYes check.svgYes check.svgSAML 1.1, SAML 2.0, OAuth 2, OpenID, LDAP, Federation
adAS SSO [4] PRiSEOSSYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0, SAML 1.0, Google, Microsoft365, Facebook, Twitter, Kerberos, LDAP, Federation, OAuth2, OpenID Connect, CAS v1, CAS v2, PAPI, OpenID
ADFS 1.x MicrosoftCommercialYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 1.0
ADFS 2.0 MicrosoftCommercialYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 1.1/2.0
ADFS 2.1 MicrosoftCommercialYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0
ADFS 3.0 MicrosoftCommercialYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2
ADFS 4.0 MicrosoftCommercialYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect
Aerobase AerobaseOSSYes check.svgYes check.svgYes check.svgIntegrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications [5]
Afrilas [6] Able - AXS GuardCommercialYes check.svgYes check.svg SAML 2.0 Strong Authentication without usernames
Asimba [7] Asimba.orgOSSYes check.svg(Fork of OpenASelect)
AssureBridge SAMLConnect [8] AssureBridgeCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.1, SAML 2.0, OpenID, WS-Federation, Kerberos, Radius, X509, LDAP
Auth0 [9] Auth0CommercialYes check.svgYes check.svgYes check.svgYes check.svgOAuth2, OpenID, SAML 1.1, SAML 2.0, WS-Federation, LDAP
Authentic2 [10] EntrouvertOSSYes check.svgYes check.svgOpenID 1&2, CAS 1&2, OAuth2, LDAP 2&3, PAM, RADIUS, OATH, Kerberos, X509
AuthStack [11] BuckhillCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.0, SAML 1.1, SAML 2.0, LDAP, Kerberos, X509, RADIUS, OAuth2, SOAP/REST API
BIG-IP Access Policy ManagerF5 NetworksCommercialYes check.svgYes check.svgYes check.svgSAML 2.0
Bitium [12] BitiumCommercialYes check.svgYes check.svgSAML, SAML 2.0
CA Single Sign-On [13] CA CommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.0/1/1/2.0, OAuth2, OpenID, WS-Federation
Central Authentication Server (CAS) [14] Apereo FoundationOpen sourceYes check.svgYes check.svgSAML 2.0, OAuth2, OpenID, WS-Federation
Centrify DirectControlCentrifyCommercialYes check.svgSAML, OpenID, OAuth, WS-*, LDAP, Kerberos
Ceptor [15] CeptorCommercialYes check.svgYes check.svgSAML 1.1/2.0, OAuth 2.0, WS-Federation, OpenID Connect, Kerberos
cidaas [16] cidaas by Widas ID GmbHCommercialYes check.svgYes check.svgSAML 2.0, OAuth2, OpenID Connect
Citrix Open Cloud [17] CitrixCommercialYes check.svgSSO Middleware, native service connectors
Cloud Identity ManagerMcAfeeCommercialYes check.svgSAML 2, OpenID, OAuth, XACML, LDAP v3, JM
Cloud Federation Service [18] Radiant LogicCommercialYes check.svgYes check.svgSAML 2.0, WS-Federation, OAuth 2.0, OpenID
Cloudseal [19] CloudsealSaaSYes check.svgYes check.svg
Cognito [20] AmazonCommercialYes check.svgSAML 2.0
Comfact IDP [21] ComfactCommercialYes check.svg
Signicat [22] SignicatCommercialYes check.svgYes check.svg
Corto project home GÉANT OSSYes check.svg
DACS [23] Safran Identity & SecurityCommercialYes check.svgYes check.svgSSO, OpenID Connect, OATH & OCRA, SMS, X509v3 Certificate, eID card, FIDO UAF, LDAP/AD, multi-factor
Dot Net Workflow [24] The Dot Net FactoryCommercialYes check.svgYes check.svgYes check.svgYes check.svgWS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN)
DirX Access [25] Atos/SiemensCommercialYes check.svgYes check.svgYes check.svg
DualShield [26] Deepnet SecurityCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0
Elastic SSO Team [27] 9STARCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0 SAML 1.1
Elastic SSO Enterprise [28] 9STARCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0 SAML 1.1
ESOEQueensland University of TechnologyOSSYes check.svgYes check.svg
Entra ID (formerly known as Azure Active Directory)MicrosoftCommercialYes check.svgYes check.svgYes check.svgSAML 2.0, WS-Federation, Kerberos Constrained Delegation, OAuth 2.0, OpenID Connect
Entrust GetAccess [29] EntrustCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.0, SAML 1.1, SAML 2.0
Entrust IdentityGuard [30] EntrustCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0, OpenID
EIC [31] EricssonCommercialYes check.svg
EmpowerID [32] The Dot Net FactoryCommercialYes check.svgYes check.svgWS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN)
Evidian Web Access ManagerEvidianCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.1, SAML 2.0, OpenID Connect, CAS 1&2, OAuth2, LDAP v3, RADIUS, OATH, Kerberos, X509, Microsoft365, Google, Multi-factor, SSO, extended integration functionalities, Federation
Fluig IdentityTOTVSCommercialYes check.svgYes check.svgSAML 2.0
Forum Sentry [33] Forum SystemsCommercialYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, SAML 1.1, OAuth 1.0.a. OAuth 2, OpenID Connect
Fugen Cloud ID BrokerFugen SolutionsCommercialYes check.svgSAML 1.1, SAML 2.0, WS-Federation, WS-Trust, OpenID, and OAuth
FusionAuth [34] FusionAuthCommercialYes check.svgYes check.svgSAML 2.0, OIDC, OAuth, LDAP
GlobalSign SSOGMO GlobalSignCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0, ETSI MSS 102 204, TUPAS, WS-Federation, OpenID
Gluu Server [36] GluuOSSYes check.svgYes check.svgYes check.svgOpenID Connect, UMA, RADIUS, LDAP, FIDO, OAuth
Hitachi ID Identity and Access Management Suite [37] Hitachi ID Systems, Inc.CommercialYes check.svgYes check.svgSAML 2.0
Horizon App Manager [38] VMwareCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svg ?
HP IceWall SSO [39] HPCommercialYes check.svgSAML 2
ILANTUS Sign On Express [40] IlantusCommercialYes check.svgYes check.svgSAML 2
Intel Cloud SSO [41] IntelCommercialYes check.svgYes check.svgSAML 2, OpenID, OAuth
Ilex Sign&go [42] ILEXCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, SAML 1.0, Shibboleth, CAS, Google, Microsoft365, Facebook, Kerberos, LDAP
iSAML [43] AvocoCommercialYes check.svgSAML 2, WS-Trust, OpenID
iWelcome [44] iWelcomeCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 2, SAML 1.0, WS-Trust, Kerberos, OAuth2, Facebook, google, includes provisioning from-to on-Prem, AD, Multi-factor, extended integration functionalities
JOSSO (Community Ed.) [45] josso.orgOSSYes check.svgYes check.svgYes check.svgSAML2, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1
JOSSO (Enterprise Ed.) [46] AtricoreCommercialYes check.svgYes check.svgYes check.svgSAML2, WS-Fed, OpenID Connect, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1
Juniper SSL VPN [47] Juniper NetworksCommercialYes check.svgYes check.svg
Keycloak JBossOSSYes check.svgIntegrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications [48]
Layer 7 [49] SecureSpan GatewayCommercialYes check.svgYes check.svgPDP/PEP, Auth2, SAML 1.1, SAML2, ABAC, OpenID Connect, XML Firewall
Larpe [50] EntrouvertOSSYes check.svgYes check.svgYes check.svgSAML, OpenID, CAS, OAuth
LemonLDAP::NG [51] LemonLDAP::NGOSSYes check.svgYes check.svgSSO, WS-Federation, CAS, OpenID-Connect, SAML-2, Twitter, Protocol proxy
LoginRadiusLoginRadiusCommercialYes check.svgYes check.svgWeb SSO, Federation SSO, SAML, OAuth, OIDC, WS-Federation, JWT
MicroFocus (NetIQ) Access Manager [52] NetIQ (formerly Novell)CommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svg
+ SP Broker
WS-Security, WS-Federation, WS-Trust, SAML 1.1 / 2.0, Liberty, Single Sign-on, RBAC, CardSpace, OAuth 2.0, OpenID, STS. Includes out of the box integration with cloud and social media providers (Office 365, Windows Live (MSN), Google, Facebook, Salesforce, Amazon web services and 200+ preconfigured connections to SaaS providers etc.) Integration for Advanced Authentication Framework
miniOrangeminiOrangeCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svg
+ Identity Broker
SAML 2.0, OAuth2, OpenID Connect, WS-Fed
NetWeaver Appserver [53] SAPCommercial ?CAS, OpenId, Twitter
OneGate [54] MobilityGuardCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.1, SAML 2.0
OpenAM Open Identity Community , ForgeRock (ex. Sun) until 2016 [55] CDDLYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgOpenID Connect, OAuth2, SAML 2.0, SAML 1.1, WS-Federation, WS-Trust, XACML, Liberty, Kerberos, Facebook, Google, Windows Live (MSN)
Okta [56] OktaCommercialYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect
OneLogin [57] OneLoginCommercialYes check.svgYes check.svgSAML, WS-Federation, Kerberos, OAuth, OpenID
OpenAthens LA [58] eduservCommercialYes check.svg
OpenAthens SP [59] eduservCommercialYes check.svg
Open Select [60] OpenASelect.orgOSSYes check.svgOAuth (project continues as asimba)
Optimal IdM VIS Federation Services [61] Optimal IdMCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svg + Proxy, SSOWS-Federation, WS-Trust, SAML 1.x, SAML 2.0, OAuth2, OpenID Connect, SCIM, Facebook, Twitter, LinkedIn, Google, IWA, X509, Kerberos, LDAP, Office 365, RADIUS, MFA (Push, SMS, Email, Voice, TOTP, U2F, Radius)
Oracle Identity Federation 11g [62] Oracle CommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, SAML 1.x, SAML 2.0, OpenID 2.0
Pega 7 Platform [63] Pegasystems Inc. CommercialYes check.svgYes check.svgYes check.svgYes check.svgSAML 2.0, OAuth, WS-Trust, LDAP
PhoneFactor [64] PhoneFactor, IncCommercialYes check.svg
PicketLink [65] JBoss CommunityOSSOpenID, A-Select, CAS, XACML
PingFederate [66] Ping IdentityCommercialYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.1, SAML 2.0, WS-Federation, WS-Trust, WS-Security, OAuth, OpenID Connect, OpenID, SCIM, Facebook, Twitter, LinkedIn, Google, Windows Live, Kerberos, IWA, X.509, LDAP, RADIUS, 3rd Party MFA
Plurilock AI [67] PlurilockCommercialYes check.svgYes check.svgSAML 1.1, SAML 2.0, FIDO2, OTP, DEFEND [68]
PortalGuard [69] PistolStar, Inc.CommercialYes check.svgYes check.svgSAML 2, LDAP v3, XML-DSIG, SSO Middleware
RSA Federated Identity [70] RSACommercialYes check.svgYes check.svgYes check.svgFacebook, OpenID, LinkedIn, Twitter, Windows Live
SAASPASSSAASPASSCommercialYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, LDAP
Safewhere*Identify [71] SafewhereCommercialYes check.svgYes check.svgSAML 2.0, WS-Federation, WS-Trust, OAuth 2.0, multi-factor, OpenID Connect, Facebook, LinkedIn, Twitter, LiveID, Google, LDAP
SailPoint IdentityNow [72] SailPointCommercialYes check.svgYes check.svgSAML 1.1, SAML 2.0, OAuth2, Kerberos, WS-Federation
Samanage [73] SamanageCommercialYes check.svgEnterprise-to-cloud SSO Middleware
SATOSA [74] SATOSAOSSYes check.svgProxy between SAML2, OpenID Connect and OAuth2
SecureAuth [75] SecureAuth Corp.CommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svg2-Factor, IBM LTPA, Facebook, Google, LinkedIn, Microsoft FBA, Microsoft IWA, OAUTH, OpenID, OpenID Connect, SAML 1.1, SAML 2.0, Twitter, WebServices, Windows Live, X.509v3, Yahoo
SecureSSO [76] SurePassIDCommercialYes check.svgYes check.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, O365, SCADA - cloud & on-prem
Shibboleth Internet2OSSYes check.svgYes check.svgYes check.svgSAML 1.1, SAML 2.0
SimpleSAMLphp [77] UNINETT AS OSSYes check.svgYes check.svgOpenID, A-Select, CAS, WS-Federation and OAuth, Facebook, LinkedIn, Twitter, Windows Live, SAML 2
Smartsignin [78] PerfectCloudCommercialYes check.svgYes check.svgSAML 2.0, SAML 1.0, Google, Microsoft365, LDAP, WS-Federation
SMS PASSCODE Multi-factor Authentication [79] SMS PASSCODECommercial ?
SSO EasyConnect [80] SSO EasyCommercialYes check.svgYes check.svg
SSOgen SSOGEN CorporationCommercialYes check.svgYes check.svgSAML 1.1, SAML 2.0, OAuth2, OpenID Connect, OpenID Provider, RADIUS, LDAP, Multi Factor Authentication.

Cloud SSO Solution for enterprises to protect on-premise applications such as SSOgen for Oracle EBS, SSOgen for PeopleSoft, SSOgen for JDE, and SSOgen for SAP, with a web server plug-in and Cloud SaaS applications with SAML, OpenID Connect integrations.

Symlabs Federated Identity Suite [81] SymlabsCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgOpenID, A-Select, CAS, WS-Federation and OAuth
Symplified [82] SymplifiedCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgSAML 1.1, SAML 2.0, WS-Federation, OpenID, OAuth, XACML, IBM LTPA, Microsoft IWA, 2-Factor, Facebook, Google, Twitter, ABAC / context-based AC
Tivoli Federated Identity Manager [83] IBMCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgWS-Federation, OpenID, Liberty, InfoCard, Microsoft CardSpace
TrustBind [84] NTT Software CorpCommercialYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgOpenID, ID-WSF
TrustBuilder [85] SecurITCommercialYes check.svgYes check.svgYes check.svgSAML 2.0, OAuth 2.0, OpenID Connect, Kerberos
Trustelem [86] TrustelemCommercialYes check.svgSAML 2.0, OpenID Connect, WS-Fed, OAuth 2.0, Integrated Windows Authentication, Kerberos, Active Directory, LDAP, FIDO U2F.
USP Secure Entry Server [87] United Security ProvidersCommercialYes check.svgYes check.svgYes check.svgSAML 2.0, SAML 1.0, Kerberos, NTLM, LDAP, RADIUS, RSA, SuisseID, RBAC, SSO, Tomcat Authenticator, IIS ISAPI Filter, mTAN, PKI/X.509, Reverse Proxy, Multi-Factor, SOAP/REST Connectors, WebService Security, Office365, GoogleApps
WeblogicOracleCommercialYes check.svg
WSO2 [88] wso2OSSYes check.svgYes check.svgOAuth2, WS-Trust, OpenID
ZITADEL [89] ZITADELOSSYes check.svgYes check.svgSAML 2.0, OpenID Connect 1.0, OAuth 2.0, FIDO2, OTP, U2F
ZXID [90] zxidOSSYes check.svgYes check.svgYes check.svgYes check.svgYes check.svgID-WSF2, XACML2, WS-Security, XML-DSIG, TAS3

Libraries and toolkits to develop SAML actors and SAML-enabled services

Libraries and toolkits are used by developers to integrate applications and services into SAML federations or to build their own SAML-actors like IdPs.

Libraries and ToolkitsOrganizationLicencePurpose and Language bindings
Australian Access Federation [91] Australian Access FederationOSSMetadata Registry based on former work by SWITCH
ComponentSpace [92] ComponentSpaceCommercialSAML libraries for ASP.NET and ASP.NET Core applications
Corto [93] WAYFOSSSAML2 proxy, virtual IdP, user consent
DjangoSAML2 [94] GitHubOSSSAML2 application for Django, using PySAML2 underneath
EmpowerID IdP & SP Kit [95] Dot Net FactoryCommercialIdP and SP Kit, .NET, REST, and SOAP-based integration kit to SAML-enable applications
FEMMA [96] SourceForgeOSSWorkaround for the ADFS limitation of a single EntityID per XML infoset
Firefox ECP Plugin [97] OpenlibertyOSSFirefox extension for compliance with SAML ECP
FLOG F-Ticks Vizualization [98] SUNETOSSParse and chart F-Ticks for webSSO and Eduroam (sample site: http://flog.sunet.se/)
Jagger [99] HEAnet OSSMetadata and Federation data manager; Shibboleth IDP GUI
JAKOB [100] WAYFOSSBackchannel attribute collector
JANUS [101] WAYFOSSMetadata Registry for hub-and-spoke federations based on SimpleSAMLphp; includes self-service
Jitbit ASP.NET SAML lib [102] GitHubOSSSAML 2.0 "consumer" component for ASP.NET
Lasso [103] EntrouvertOSSSAML-Library: C/C++, Python, Java, Perl, PHP
LightSAML core [104] OSSSAML-Library: PHP
OIOSAML 2.0 Toolkit [105] Danish IT and Telekom Agency OSSSP Framework: Java, .NET, [106] PHP (Documentation see OIOSAML.java)
OmniAuth-Shibboleth [107] OneLogin OSSSAML-Library: ASP/.NET, Java, PHP, Python, Ruby
OneLogin [108] OneLogin OSSSAML-Library: ASP/.NET, Java, PHP, Python, Ruby
OpenConext [109] SURFnet OSSService Provider Proxy and Hub-and-Spoke federation middleware, includes SAML proxy and central group management for creating collaboration platforms
OpenSAML [110] Internet2 OSSSAML-Library: C++, Java
MET [111] TERENA OSSgathers and shows information about federations (mostly about SPs and IdPs)
Mujina [112] SURFnet OSSSAML test actors that can be dynamically configured using a REST interface
PAC4J-SAML [113] OSSSAML Service Provider Library (and other authentication mechanisms)
PEER [114] GÉANTOSSSAML Metadata Registry
PHPH [115] WAYF.dkOSSSAML Metadata Processor
Ping Identity [116] Ping IdentityCommercialJava, .NET, PHP and language neutral integration kits to SAML-enable applications
PySAML2 [117] GitHubOSSSAML-Library: Python
Python-SAML OneLogin OSSSAML-Library: Python
Pysfemma [118] GitHubOSSautomate membership configuration of an ADFS STS in a SAML2 based Identity Federation
PyFF [119] SUNET OSSSAML Metadata Processor
Raptor [120] Jisc OSStoolkit to enable Shibboleth IdP statistics analysis
SAML Metadata Aggregator [121] NORDUnet OSSAggregates single metadata files and provides MDX webservice
SAML Tracer (Firefox addon) [122] UNINETT AS OSSFirefox Plug-In to trace SAML messages
SecureBlackbox [123] /n softwareCommercialThe component that implements SAML in client apps, which need to use service providers, or can be used to create your own service and identity providers
SpringSecurity SAML [124] SpringSource OSSSAML-enable applications based on Spring framework
Switch GMT [125] SWITCH-AAIOSSGroup Management Tool for Shibboleth
Ultimate SAML [126] ComponentProCommercialSAML 1.1 and 2.0 Libraries for .NET
Webisoget [127] OSSCommand-line Tool to fetch a SSO-protected page including Shibboleth-Login
ZXID [128] zxidOSSC, other lang using swig.org

This section lists public services such as identity and attribute providers, metadata and test services, but *not* SAML-enabled web-applications and cloud services.

ServiceOrganizationPurpose
9STAR [129] 9STAR9STAR Managed Services for Shibboleth/SAML SSO On-Premises or Cloud
9STAR [130] 9STAR9STAR Shibboleth/SAML SSO Support Services
Acrot A-OK [131] ArcotIdP (+ Fraud detection)
eduTEAMs [132] SURFnet Federation enabled Group management service which acts as an Attribute Authority for group relations
Federation Lab [133] GÉANT Test-SP, metadata registry, test tools
Feide OpenIdP [134] UNINETT AS IdP that allows any user to register, and any SP to connect
Gazelle IHE validator [135] GazelleSAML Assertion Validation
Gluu On-Prem Managed Service [136] Gluu IdP for SAML and OpenID Connect-enabled cloud services
Identity Hub [137] EntrouvertFree IdP; Any user and any SP
OneLogin SSO [138] OneLogin IdP for SAML- and OpenID-enabled cloud services
REEP [139] GÉANT Public metadata registry
PhoneFactor [140] PhoneFactor Inc.IdP/cloud SSO
PingOne [141] Ping IdentityCloud Access and Application Provider Services for IdPs and SPs
SAASPASSSAASPASSIdP, IdM, Multi-Protocol STS (multiple claims based integrations including SAML 1.1, 2.0 SP SSO, 2.0 IdP SSO, OpenID Connect, .NET, CA SiteMinder and others
SamlComponent.net [142] SamlComponentSAML Resources for Developers
samlidp.io [143] Kitek Media Kft.SAML Identity Provider as a Service
SecureAuth [144] SecureAuth Corp.IdP, IdM, Multi-Protocol STS (multiple claims based integrations including SAML 1.1, 2.0 SP SSO, 2.0 IdP SSO, OpenID, .NET, CA SiteMinder and others
SSOCircle [145] SSOCircleFree IdP
Testshib [146] Internet2 IdP and SP for testing
UnitedID [147] United ID ServicesFree IDP service
Verizon Web Access Management [148] Verizon Business IdP
ZXID [149] zxid.orgFree IdP

Related Research Articles

Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single ID to any of several related, yet independent, software systems.

Identity management (IdM), also known as identity and access management, is a framework of policies and technologies to ensure that the right users have the appropriate access to technology resources. IdM systems fall under the overarching umbrellas of IT security and data management. Identity and access management systems not only identify, authenticate, and control access for individuals who will be utilizing IT resources but also the hardware and applications employees need to access.

Java Authentication and Authorization Service, or JAAS, pronounced "Jazz", is the Java implementation of the standard Pluggable Authentication Module (PAM) information security framework. JAAS was introduced as an extension library to the Java Platform, Standard Edition 1.3 and was integrated in version 1.4.

<span class="mw-page-title-main">Liberty Alliance</span> Computer trade group

The Liberty Alliance Project was an organization formed in September 2001 to establish standards, guidelines and best practices for identity management in computer systems. It grew to more than 150 organizations, including technology vendors, consumer-facing companies, educational organizations and governments. It released frameworks for federation, identity assurance, an Identity Governance Framework, and Identity Web Services.

Security Assertion Markup Language is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. SAML is an XML-based markup language for security assertions. SAML is also:

The Central Authentication Service (CAS) is a single sign-on protocol for the web. Its purpose is to permit a user to access multiple applications while providing their credentials only once. It also allows web applications to authenticate users without gaining access to a user's security credentials, such as a password. The name CAS also refers to a software package that implements this protocol.

A federated identity in information technology is the means of linking a person's electronic identity and attributes, stored across multiple distinct identity management systems.

<span class="mw-page-title-main">Shibboleth (software)</span> Internet identity system

Shibboleth is a single sign-on log-in system for computer networks and the Internet. It allows people to sign in using just one identity to various systems run by federations of different organizations or institutions. The federations are often universities or public service organizations.

Security Assertion Markup Language (SAML) is an XML standard for exchanging authentication and authorization data between security domains. SAML is a product of the OASIS (organization) Security Services Technical Committee.

Security Assertion Markup Language 2.0 (SAML 2.0) is a version of the SAML standard for exchanging authentication and authorization identities between security domains. SAML 2.0 is an XML-based protocol that uses security tokens containing assertions to pass information about a principal between a SAML authority, named an Identity Provider, and a SAML consumer, named a Service Provider. SAML 2.0 enables web-based, cross-domain single sign-on (SSO), which helps reduce the administrative overhead of distributing multiple authentication tokens to the user. SAML 2.0 was ratified as an OASIS Standard in March 2005, replacing SAML 1.1. The critical aspects of SAML 2.0 are covered in detail in the official documents SAMLCore, SAMLBind, SAMLProf, and SAMLMeta.

Web Single Sign-On Interoperability Profile is a Web Services and Federated identity specification, published by Microsoft and Sun Microsystems that defines interoperability between WS-Federation and the Liberty Alliance protocols.

Web Single Sign-On Metadata Exchange Protocol is a Web Services and Federated identity specification, published by Microsoft and Sun Microsystems that defines mechanisms for a service to query an identity provider for metadata concerning the protocol suites it supports. The goal of this operation is to increase the ability of a given service to interoperate with a given identity provider.

Identity assurance in the context of federated identity management is the ability for a party to determine, with some level of certainty, that an electronic credential representing an entity with which it interacts to effect a transaction, can be trusted to actually belong to the entity.

<span class="mw-page-title-main">OpenAM</span>

OpenAM is an open-source access management, entitlements and federation server platform. Now it is supported by Open Identity Platform Community.

An identity provider is a system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network.

User-Managed Access (UMA) is an OAuth-based access management protocol standard for party-to-party authorization. Version 1.0 of the standard was approved by the Kantara Initiative on March 23, 2015.

OpenAthens is an identity and access management service, supplied by Jisc, a British not-for-profit information technology services company. Identity provider (IdP) organisations can keep usernames in the cloud, locally or both. Integration with ADFS, LDAP or SAML is supported.

The SAML metadata standard belongs to the family of XML-based standards known as the Security Assertion Markup Language (SAML) published by OASIS in 2005. A SAML metadata document describes a SAML deployment such as a SAML identity provider or a SAML service provider. Deployments share metadata to establish a baseline of trust and interoperability.

A SAML identity provider is a system entity that issues authentication assertions in conjunction with a single sign-on (SSO) profile of the Security Assertion Markup Language (SAML).

References

  1. "Kantara Initiative 2011 Q1 SAML 2.0 Full-Matrix Interoperability Testing".
  2. "Liberty Alliance SAML interoperability tests". 12 November 2021.
  3. "10Duke Identity Provider". 11 February 2022.
  4. "adAS SSO".
  5. "Aerobase". Aerobase Org.
  6. "Afrilas".
  7. "Asimba".
  8. "AssureBridge".
  9. "Auth0". Auth0. Retrieved 2019-12-12.
  10. "Authentic2".
  11. "Authstack - Identity Access Management (IAM) and Single Sign-On Software". www.buckhill.co.uk. Retrieved 2017-05-15.
  12. "Bitium Single Sign-on".
  13. "CA Federation Manager".
  14. "CAS SAML2 Authentication".
  15. "Secure IT Infrastructure for Online Business Applications | Ceptor". Ceptor. Retrieved 2018-02-26.
  16. "cidaas – European Cloud Identity and Access Management". cidaas. Retrieved 2020-11-21.
  17. "Citrix Open Cloud Access".
  18. "RadiantOne Cloud Federation Service".
  19. "Cloudseal SSO for Java".
  20. "Amazon Cognito: SAML identity providers (identity pools)".
  21. "Comfact IDP".
  22. "Signicat".
  23. "Morpho DACS" (PDF).
  24. "Dot Net Workflow cloud and corporate SSO and Federation".
  25. "DirX Access".
  26. "DualShield unified authentication platform".
  27. "9STAR's Elastic SSO Team". 16 October 2018.
  28. "9STAR's Elastic SSO Enterprise". 16 October 2018.
  29. "Entrust GetAccess".
  30. "Entrust IdentityGuard".
  31. "EIC".
  32. "EmpowerID".
  33. "API Security Gateway".
  34. "FusionAuth Community Edition".
  35. "GlobalSign SSO". Globalsign. 30 March 2020.
  36. "Open Source Access Management".
  37. "IAM Solutions".
  38. "Horizon App Manager".
  39. "HP IceWall SSO".
  40. "ILANTUS Xpress Sign-On". 10 September 2019.
  41. "Intel Cloud SSO".
  42. "Ilex".
  43. "Avoco Identity".
  44. "iWelcome".
  45. "JOSSO (Community Edition)".
  46. "JOSSO (Enterprise Edition)".
  47. "Juniper SSL VPN" (PDF).
  48. "Keycloak". JBoss Community.
  49. "Layer 7".
  50. "Larpe".
  51. "LemonLDAP::NG".
  52. "NetIQ Access Manager".
  53. "NetWeaver Appserver".
  54. "Mobilityguard OneGate". mobilityguard.com. Retrieved 2016-02-20.
  55. "ForgeRock has shuttered the open-source community, and no longer allows new development on their platform under a permissive license". timeforafork. June 1, 2017. Retrieved June 1, 2017.
  56. "Cloud service platform".
  57. "OneLogin Single Sign On".
  58. "OpenAthens LA".
  59. "OpenAthens SP".
  60. "OpenASelect".
  61. "Optimal IdM VIS Federation Services".
  62. "Oracle Identity Federation 11g".
  63. "Pega7". 15 September 2020.
  64. "PhoneFactor".
  65. "PicketLink".
  66. "PingFederate".
  67. "Plurilock AI Cloud".
  68. "DEFEND Continuous Authentication".
  69. "PortalGuard".
  70. "RSA Federated Identity Manager".
  71. "Safewhere*Identify".
  72. "SailPoint IdentityNow".
  73. "Samanage".
  74. "Github/SATOSA". GitHub . 25 October 2021.
  75. "SecureAuth".
  76. "SurePassID".
  77. "SimpleSAMLphp".
  78. "Smartsignin Single Sign-on".
  79. "SMS PASSCODE".
  80. "SSO EasyConnect".
  81. "Symlabs Federated Identity Suite".
  82. "Symplified".
  83. "Tivoli Federated Identity Manager". 9 November 2020.
  84. "TrustBind/Federation Manager".
  85. "TrustBuilder".
  86. "Trustelem Cloud SSO | Active Directory and multi-factor authentication". www.trustelem.com. Retrieved 2017-05-15.
  87. "USP Secure Entry Server".
  88. "WSO2".
  89. "ZITADEL".
  90. "ZXID".
  91. "Federation Registry".
  92. "ComponentSpace".
  93. "cortoweb".
  94. "knaperek/djangosaml2". GitHub. Retrieved 2016-06-08.
  95. "EmpowerID Dot Net Workflow Idp & SP Kit".
  96. "Federation Metadata Manager for ADFS".
  97. "Firefox ECP Plugin".
  98. "FLOG". GitHub . 8 May 2020.
  99. "JAGGER (ResourceRegistry3". GitHub . 20 October 2021.
  100. "JAKOB Attribute Collector".
  101. "JANUS". GitHub . 21 March 2020.
  102. "Jitbit SAML toolkil". GitHub . 13 April 2022.
  103. "Lasso".
  104. "LightSAML core".
  105. "OIOSAML 2.0 Toolkit".
  106. "OIOSAM.net Service Provider Framework" (PDF).
  107. "Shibboleth Binding for OmniAuth 1.x". GitHub . 16 December 2020.
  108. "SAML Toolkits from OneLogin".
  109. "OpenConext".
  110. "OpenSAML".
  111. "Metadata Explorer Tool". GitHub . 14 January 2021.
  112. "Mujina Mock IdP and SP". GitHub . 13 April 2022.
  113. "PAC4J Security Engine".
  114. "PEER". GitHub . 26 June 2018.
  115. "PHPH". GitHub . 7 June 2015.
  116. "PingFederate Integration Kits".
  117. "PySAML2". GitHub . 13 April 2022.
  118. "Pysfemma". GitHub . 28 January 2019.
  119. "PyFF".
  120. "Raptor".
  121. "SAML Metadata Aggregator".
  122. "SAML Tracer".
  123. "SAMLBlackbox (SAML component and class library) - SecureBlackbox". www.secureblackbox.com. Retrieved 2019-02-20.
  124. "SpringSecurity SAML Site".
  125. "SWITCH Group Management Tool".
  126. "Ultimate SAML".
  127. https://wiki.edugain.org/Webisoget
  128. "ZXID".
  129. "9STAR Shibboleth/SAML SSO Services". 23 October 2018.
  130. "9STAR Shibboleth/SAML SSO Support". 16 October 2018.
  131. "Arcot A-OK".
  132. "eduTEAMs".
  133. "Federation Lab".
  134. "Feide OpenIdP".
  135. "Gazelle IHE interop test framework".
  136. "Gluu On-Prem Managed Service".
  137. "Identity Hub".
  138. "OneLogin SSO".
  139. "RE:EP".
  140. "Phonefactor".
  141. "PingOne".
  142. "SAML .NET Dev Zone".
  143. "samlidp.io - SAML Identity Provider as a Service". samlidp.io. Retrieved 2017-03-21.
  144. "SecureAuth Corp".
  145. "SSO Circle IDP".
  146. "Testshib.org".
  147. "United ID".
  148. "Verizon Web Access Management as a Service".
  149. "ZXIDP.org".

{{ | url=https://www.miniorange.com/ | title=Cloud/On-Premise service platform}}