SAML-based products and services

Last updated

Security Assertion Markup Language (SAML) is a set of specifications that encompasses the XML-format for security tokens containing assertions to pass information about a user and protocols and profiles to implement authentication and authorization scenarios. This article has a focus on software and services in the category of identity management infrastructure, which enable building Web-SSO solutions using the SAML protocol in an interoperable fashion. Software and services that are only SAML-enabled do not go here.

Contents

Products that provide SAML actors

SAML actors are Identity Providers (IdP), Service Providers (SP), Discovery Services, ECP Clients, Metadata Services, or Broker/IdP-proxy. This table shows the capability of products according to Kantara Initiative testing. [1] [2] Claimed capabilities are in column "other". Each mark denotes that at least one interoperability test was passed. Detailed results with product and test procedure versions are available at the Kantara/Liberty site given below.

NOTE: This table represents a snapshot over time roll up of the most recent product test results (multiple testing rounds). Please note that some products features and abilities may have been updated since they were last tested. Please check the website information of the originating product for the latest features and updates.

Product NameProject/VendorLicenseKantara-certified InteroperabilityOther Features
IdP
IdP Light
SP
SP Light
eGov 1.5
Attr Auth Resp
POST Bind.
RolesProtocols
Broker
Discovery
ECP
IdP
IdP Proxy
Reverse Proxy
SP
10Duke Identity Provider [3] 10DukeCommercialCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, OAuth 2, OpenID, LDAP, Federation
adAS SSO [4] PRiSEOSSCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, SAML 1.0, Google, Microsoft365, Facebook, Twitter, Kerberos, LDAP, Federation, OAuth2, OpenID Connect, CAS v1, CAS v2, PAPI, OpenID
ADFS 1.x MicrosoftCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 1.0
ADFS 2.0 MicrosoftCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 1.1/2.0
ADFS 2.1 MicrosoftCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0
ADFS 3.0 MicrosoftCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2
ADFS 4.0 MicrosoftCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect
Aerobase [5] AerobaseOSSCheck-green.svgCheck-green.svgCheck-green.svgIntegrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications [6]
Afrilas [7] Able - AXS GuardCommercialCheck-green.svgCheck-green.svg SAML 2.0 Strong Authentication without usernames
Asimba [8] Asimba.orgOSSCheck-green.svg(Fork of OpenASelect)
AssureBridge SAMLConnect [9] AssureBridgeCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, OpenID, WS-Federation, Kerberos, Radius, X509, LDAP
Auth0 [10] Auth0CommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgOAuth2, OpenID, SAML 1.1, SAML 2.0, WS-Federation, LDAP
Authentic2 [11] EntrouvertOSSCheck-green.svgCheck-green.svgOpenID 1&2, CAS 1&2, OAuth2, LDAP 2&3, PAM, RADIUS, OATH, Kerberos, X509
AuthStack [12] BuckhillCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.0, SAML 1.1, SAML 2.0, LDAP, Kerberos, X509, RADIUS, OAuth2, SOAP/REST API
BIG-IP Access Policy ManagerF5 NetworksCommercialCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0
Bitium [13] BitiumCommercialCheck-green.svgCheck-green.svgSAML, SAML 2.0
CA Single Sign-On [14] CA CommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.0/1/1/2.0, OAuth2, OpenID, WS-Federation
Central Authentication Server (CAS) [15] Apereo FoundationOpen sourceCheck-green.svgCheck-green.svgSAML 2.0, OAuth2, OpenID, WS-Federation
Centrify DirectControlCentrifyCommercialCheck-green.svgSAML, OpenID, OAuth, WS-*, LDAP, Kerberos
Ceptor [16] CeptorCommercialCheck-green.svgCheck-green.svgSAML 1.1/2.0, OAuth 2.0, WS-Federation, OpenID Connect, Kerberos
cidaas [17] cidaas by Widas ID GmbHCommercialCheck-green.svgCheck-green.svgSAML 2.0, OAuth2, OpenID Connect
Citrix Open Cloud [18] CitrixCommercialCheck-green.svgSSO Middleware, native service connectors
Cloud Identity ManagerMcAfeeCommercialCheck-green.svgSAML 2, OpenID, OAuth, XACML, LDAP v3, JM
Cloud Federation Service [19] Radiant LogicCommercialCheck-green.svgCheck-green.svgSAML 2.0, WS-Federation, OAuth 2.0, OpenID
Cloudseal [20] CloudsealSaaSCheck-green.svgCheck-green.svg
Cognito [21] AmazonCommercialCheck-green.svgSAML 2.0
Comfact IDP [22] ComfactCommercialCheck-green.svg
Signicat [23] SignicatCommercialCheck-green.svgCheck-green.svg
Corto project home GÉANT OSSCheck-green.svg
DACS [24] Safran Identity & SecurityCommercialCheck-green.svgCheck-green.svgSSO, OpenID Connect, OATH & OCRA, SMS, X509v3 Certificate, eID card, FIDO UAF, LDAP/AD, multi-factor
Dot Net Workflow [25] The Dot Net FactoryCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN)
DirX Access [26] Atos/SiemensCommercialCheck-green.svgCheck-green.svgCheck-green.svg
DualShield [27] Deepnet SecurityCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0
Elastic SSO Team [28] 9STARCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0 SAML 1.1
Elastic SSO Enterprise [29] 9STARCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0 SAML 1.1
ESOEQueensland University of TechnologyOSSCheck-green.svgCheck-green.svg
Entra ID (formerly known as Azure Active Directory)MicrosoftCommercialCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, WS-Federation, Kerberos Constrained Delegation, OAuth 2.0, OpenID Connect
Entrust GetAccess [30] EntrustCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.0, SAML 1.1, SAML 2.0
Entrust IdentityGuard [31] EntrustCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, OpenID
EIC [32] EricssonCommercialCheck-green.svg
EmpowerID [33] The Dot Net FactoryCommercialCheck-green.svgCheck-green.svgWS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN)
Evidian Web Access ManagerEvidianCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, OpenID Connect, CAS 1&2, OAuth2, LDAP v3, RADIUS, OATH, Kerberos, X509, Microsoft365, Google, Multi-factor, SSO, extended integration functionalities, Federation
Fluig IdentityTOTVSCommercialCheck-green.svgCheck-green.svgSAML 2.0
Forum Sentry [34] Forum SystemsCommercialCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, SAML 1.1, OAuth 1.0.a. OAuth 2, OpenID Connect
Fugen Cloud ID BrokerFugen SolutionsCommercialCheck-green.svgSAML 1.1, SAML 2.0, WS-Federation, WS-Trust, OpenID, and OAuth
FusionAuth [35] FusionAuthCommercialCheck-green.svgCheck-green.svgSAML 2.0, OIDC, OAuth, LDAP
GlobalSign SSOGMO GlobalSignCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, ETSI MSS 102 204, TUPAS, WS-Federation, OpenID
Gluu Server [37] GluuOSSCheck-green.svgCheck-green.svgCheck-green.svgOpenID Connect, UMA, RADIUS, LDAP, FIDO, OAuth
Hitachi ID Identity and Access Management Suite [38] Hitachi ID Systems, Inc.CommercialCheck-green.svgCheck-green.svgSAML 2.0
Horizon App Manager [39] VMwareCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svg ?
HP IceWall SSO [40] HPCommercialCheck-green.svgSAML 2
ILANTUS Sign On Express [41] IlantusCommercialCheck-green.svgCheck-green.svgSAML 2
Intel Cloud SSO [42] IntelCommercialCheck-green.svgCheck-green.svgSAML 2, OpenID, OAuth
Ilex Sign&go [43] ILEXCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, SAML 1.0, Shibboleth, CAS, Google, Microsoft365, Facebook, Kerberos, LDAP
iSAML [44] AvocoCommercialCheck-green.svgSAML 2, WS-Trust, OpenID
iWelcome [45] iWelcomeCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2, SAML 1.0, WS-Trust, Kerberos, OAuth2, Facebook, google, includes provisioning from-to on-Prem, AD, Multi-factor, extended integration functionalities
JOSSO (Community Ed.) [46] josso.orgOSSCheck-green.svgCheck-green.svgCheck-green.svgSAML2, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1
JOSSO (Enterprise Ed.) [47] AtricoreCommercialCheck-green.svgCheck-green.svgCheck-green.svgSAML2, WS-Fed, OpenID Connect, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1
Juniper SSL VPN [48] Juniper NetworksCommercialCheck-green.svgCheck-green.svg
Keycloak JBossOSSCheck-green.svgIntegrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications [49]
Layer 7 [50] SecureSpan GatewayCommercialCheck-green.svgCheck-green.svgPDP/PEP, Auth2, SAML 1.1, SAML2, ABAC, OpenID Connect, XML Firewall
Larpe [51] EntrouvertOSSCheck-green.svgCheck-green.svgCheck-green.svgSAML, OpenID, CAS, OAuth
LemonLDAP::NG [52] LemonLDAP::NGOSSCheck-green.svgCheck-green.svgSSO, WS-Federation, CAS, OpenID-Connect, SAML-2, Twitter, Protocol proxy
LoginRadiusLoginRadiusCommercialCheck-green.svgCheck-green.svgWeb SSO, Federation SSO, SAML, OAuth, OIDC, WS-Federation, JWT
MicroFocus (NetIQ) Access Manager [53] NetIQ (formerly Novell)CommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svg
+ SP Broker
WS-Security, WS-Federation, WS-Trust, SAML 1.1 / 2.0, Liberty, Single Sign-on, RBAC, CardSpace, OAuth 2.0, OpenID, STS. Includes out of the box integration with cloud and social media providers (Office 365, Windows Live (MSN), Google, Facebook, Salesforce, Amazon web services and 200+ preconfigured connections to SaaS providers etc.) Integration for Advanced Authentication Framework
miniOrangeminiOrangeCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svg
+ Identity Broker
SAML 2.0, OAuth2, OpenID Connect, WS-Fed
NetWeaver Appserver [54] SAPCommercial ?CAS, OpenId, Twitter
OneGate [55] MobilityGuardCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0
OpenAM Open Identity Community , ForgeRock (ex. Sun) until 2016 [56] CDDLCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgOpenID Connect, OAuth2, SAML 2.0, SAML 1.1, WS-Federation, WS-Trust, XACML, Liberty, Kerberos, Facebook, Google, Windows Live (MSN)
Okta [57] OktaCommercialCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect
OneLogin [58] OneLoginCommercialCheck-green.svgCheck-green.svgSAML, WS-Federation, Kerberos, OAuth, OpenID
OpenAthens LA [59] eduservCommercialCheck-green.svg
OpenAthens SP [60] eduservCommercialCheck-green.svg
Open Select [61] OpenASelect.orgOSSCheck-green.svgOAuth (project continues as asimba)
Optimal IdM VIS Federation Services [62] Optimal IdMCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svg + Proxy, SSOWS-Federation, WS-Trust, SAML 1.x, SAML 2.0, OAuth2, OpenID Connect, SCIM, Facebook, Twitter, LinkedIn, Google, IWA, X509, Kerberos, LDAP, Office 365, RADIUS, MFA (Push, SMS, Email, Voice, TOTP, U2F, Radius)
Oracle Identity Federation 11g [63] Oracle CommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, SAML 1.x, SAML 2.0, OpenID 2.0
Pega 7 Platform [64] Pegasystems Inc. CommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, OAuth, WS-Trust, LDAP
PhoneFactor [65] PhoneFactor, IncCommercialCheck-green.svg
PicketLink [66] JBoss CommunityOSSOpenID, A-Select, CAS, XACML
PingFederate [67] Ping IdentityCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, WS-Federation, WS-Trust, WS-Security, OAuth, OpenID Connect, OpenID, SCIM, Facebook, Twitter, LinkedIn, Google, Windows Live, Kerberos, IWA, X.509, LDAP, RADIUS, 3rd Party MFA
Plurilock AI [68] PlurilockCommercialCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, FIDO2, OTP, DEFEND [69]
PortalGuard [70] PistolStar, Inc.CommercialCheck-green.svgCheck-green.svgSAML 2, LDAP v3, XML-DSIG, SSO Middleware
RSA Federated Identity [71] RSACommercialCheck-green.svgCheck-green.svgCheck-green.svgFacebook, OpenID, LinkedIn, Twitter, Windows Live
SAASPASSSAASPASSCommercialCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, LDAP
Safewhere*Identify [72] SafewhereCommercialCheck-green.svgCheck-green.svgSAML 2.0, WS-Federation, WS-Trust, OAuth 2.0, multi-factor, OpenID Connect, Facebook, LinkedIn, Twitter, LiveID, Google, LDAP
SailPoint IdentityNow [73] SailPointCommercialCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, OAuth2, Kerberos, WS-Federation
Samanage [74] SamanageCommercialCheck-green.svgEnterprise-to-cloud SSO Middleware
SATOSA [75] SATOSAOSSCheck-green.svgProxy between SAML2, OpenID Connect and OAuth2
SecureAuth [76] SecureAuth Corp.CommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svg2-Factor, IBM LTPA, Facebook, Google, LinkedIn, Microsoft FBA, Microsoft IWA, OAUTH, OpenID, OpenID Connect, SAML 1.1, SAML 2.0, Twitter, WebServices, Windows Live, X.509v3, Yahoo
SecureSSO [77] SurePassIDCommercialCheck-green.svgCheck-green.svgWS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, O365, SCADA - cloud & on-prem
Shibboleth Internet2OSSCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0
SimpleSAMLphp [78] UNINETT AS OSSCheck-green.svgCheck-green.svgOpenID, A-Select, CAS, WS-Federation and OAuth, Facebook, LinkedIn, Twitter, Windows Live, SAML 2
Smartsignin [79] PerfectCloudCommercialCheck-green.svgCheck-green.svgSAML 2.0, SAML 1.0, Google, Microsoft365, LDAP, WS-Federation
SMS PASSCODE Multi-factor Authentication [80] SMS PASSCODECommercial ?
SSO EasyConnect [81] SSO EasyCommercialCheck-green.svgCheck-green.svg
SSOgen SSOGEN CorporationCommercialCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, OAuth2, OpenID Connect, OpenID Provider, RADIUS, LDAP, Multi Factor Authentication.

Cloud SSO Solution for enterprises to protect on-premise applications such as SSOgen for Oracle EBS, SSOgen for PeopleSoft, SSOgen for JDE, and SSOgen for SAP, with a web server plug-in and Cloud SaaS applications with SAML, OpenID Connect integrations.

Symlabs Federated Identity Suite [82] SymlabsCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgOpenID, A-Select, CAS, WS-Federation and OAuth
Symplified [83] SymplifiedCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgSAML 1.1, SAML 2.0, WS-Federation, OpenID, OAuth, XACML, IBM LTPA, Microsoft IWA, 2-Factor, Facebook, Google, Twitter, ABAC / context-based AC
Tivoli Federated Identity Manager [84] IBMCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgWS-Federation, OpenID, Liberty, InfoCard, Microsoft CardSpace
TrustBind [85] NTT Software CorpCommercialCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgOpenID, ID-WSF
TrustBuilder [86] SecurITCommercialCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, OAuth 2.0, OpenID Connect, Kerberos
Trustelem [87] TrustelemCommercialCheck-green.svgSAML 2.0, OpenID Connect, WS-Fed, OAuth 2.0, Integrated Windows Authentication, Kerberos, Active Directory, LDAP, FIDO U2F.
USP Secure Entry Server [88] United Security ProvidersCommercialCheck-green.svgCheck-green.svgCheck-green.svgSAML 2.0, SAML 1.0, Kerberos, NTLM, LDAP, RADIUS, RSA, SuisseID, RBAC, SSO, Tomcat Authenticator, IIS ISAPI Filter, mTAN, PKI/X.509, Reverse Proxy, Multi-Factor, SOAP/REST Connectors, WebService Security, Office365, GoogleApps
WeblogicOracleCommercialCheck-green.svg
WSO2 [89] wso2OSSCheck-green.svgCheck-green.svgOAuth2, WS-Trust, OpenID
ZITADEL [90] ZITADELOSSCheck-green.svgCheck-green.svgSAML 2.0, OpenID Connect 1.0, OAuth 2.0, FIDO2, OTP, U2F
ZXID [91] zxidOSSCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgCheck-green.svgID-WSF2, XACML2, WS-Security, XML-DSIG, TAS3

Libraries and toolkits to develop SAML actors and SAML-enabled services

Libraries and toolkits are used by developers to integrate applications and services into SAML federations or to build their own SAML-actors like IdPs.

Libraries and ToolkitsOrganizationLicencePurpose and Language bindings
Australian Access Federation [92] Australian Access FederationOSSMetadata Registry based on former work by SWITCH
ComponentSpace [93] ComponentSpaceCommercialSAML libraries for ASP.NET and ASP.NET Core applications
Corto [94] WAYFOSSSAML2 proxy, virtual IdP, user consent
DjangoSAML2 [95] GitHubOSSSAML2 application for Django, using PySAML2 underneath
EmpowerID IdP & SP Kit [96] Dot Net FactoryCommercialIdP and SP Kit, .NET, REST, and SOAP-based integration kit to SAML-enable applications
FEMMA [97] SourceForgeOSSWorkaround for the ADFS limitation of a single EntityID per XML infoset
Firefox ECP Plugin [98] OpenlibertyOSSFirefox extension for compliance with SAML ECP
FLOG F-Ticks Vizualization [99] SUNETOSSParse and chart F-Ticks for webSSO and Eduroam (sample site: http://flog.sunet.se/)
Jagger [100] HEAnet OSSMetadata and Federation data manager; Shibboleth IDP GUI
JAKOB [101] WAYFOSSBackchannel attribute collector
JANUS [102] WAYFOSSMetadata Registry for hub-and-spoke federations based on SimpleSAMLphp; includes self-service
Jitbit ASP.NET SAML lib [103] GitHubOSSSAML 2.0 "consumer" component for ASP.NET
Lasso [104] EntrouvertOSSSAML-Library: C/C++, Python, Java, Perl, PHP
LightSAML core [105] OSSSAML-Library: PHP
OIOSAML 2.0 Toolkit [106] Danish IT and Telekom Agency OSSSP Framework: Java, .NET, [107] PHP (Documentation see OIOSAML.java)
OmniAuth-Shibboleth [108] OneLogin OSSSAML-Library: ASP/.NET, Java, PHP, Python, Ruby
OneLogin [109] OneLogin OSSSAML-Library: ASP/.NET, Java, PHP, Python, Ruby
OpenConext [110] SURFnet OSSService Provider Proxy and Hub-and-Spoke federation middleware, includes SAML proxy and central group management for creating collaboration platforms
OpenSAML [111] Internet2 OSSSAML-Library: C++, Java
MET [112] TERENA OSSgathers and shows information about federations (mostly about SPs and IdPs)
Mujina [113] SURFnet OSSSAML test actors that can be dynamically configured using a REST interface
PAC4J-SAML [114] OSSSAML Service Provider Library (and other authentication mechanisms)
PEER [115] GÉANTOSSSAML Metadata Registry
PHPH [116] WAYF.dkOSSSAML Metadata Processor
Ping Identity [117] Ping IdentityCommercialJava, .NET, PHP and language neutral integration kits to SAML-enable applications
PySAML2 [118] GitHubOSSSAML-Library: Python
Python-SAML OneLogin OSSSAML-Library: Python
Pysfemma [119] GitHubOSSautomate membership configuration of an ADFS STS in a SAML2 based Identity Federation
PyFF [120] SUNET OSSSAML Metadata Processor
Raptor [121] Jisc OSStoolkit to enable Shibboleth IdP statistics analysis
SAML Metadata Aggregator [122] NORDUnet OSSAggregates single metadata files and provides MDX webservice
SAML Tracer (Firefox addon) [123] UNINETT AS OSSFirefox Plug-In to trace SAML messages
SecureBlackbox [124] /n softwareCommercialThe component that implements SAML in client apps, which need to use service providers, or can be used to create your own service and identity providers
SpringSecurity SAML [125] SpringSource OSSSAML-enable applications based on Spring framework
Switch GMT [126] SWITCH-AAIOSSGroup Management Tool for Shibboleth
Webisoget [127] OSSCommand-line Tool to fetch a SSO-protected page including Shibboleth-Login
ZXID [128] zxidOSSC, other lang using swig.org

This section lists public services such as identity and attribute providers, metadata and test services, but *not* SAML-enabled web-applications and cloud services.

ServiceOrganizationPurpose
9STAR [129] 9STAR9STAR Managed Services for Shibboleth/SAML SSO On-Premises or Cloud
9STAR [130] 9STAR9STAR Shibboleth/SAML SSO Support Services
Acrot A-OK [131] ArcotIdP (+ Fraud detection)
eduTEAMs [132] SURFnet Federation enabled Group management service which acts as an Attribute Authority for group relations
Federation Lab [133] GÉANT Test-SP, metadata registry, test tools
Feide OpenIdP [134] UNINETT AS IdP that allows any user to register, and any SP to connect
Gazelle IHE validator [135] GazelleSAML Assertion Validation
Gluu On-Prem Managed Service [136] Gluu IdP for SAML and OpenID Connect-enabled cloud services
Identity Hub [137] EntrouvertFree IdP; Any user and any SP
OneLogin SSO [138] OneLogin IdP for SAML- and OpenID-enabled cloud services
REEP [139] GÉANT Public metadata registry
PhoneFactor [140] PhoneFactor Inc.IdP/cloud SSO
PingOne [141] Ping IdentityCloud Access and Application Provider Services for IdPs and SPs
SAASPASSSAASPASSIdP, IdM, Multi-Protocol STS (multiple claims based integrations including SAML 1.1, 2.0 SP SSO, 2.0 IdP SSO, OpenID Connect, .NET, CA SiteMinder and others
SamlComponent.net [142] SamlComponentSAML Resources for Developers
samlidp.io [143] Kitek Media Kft.SAML Identity Provider as a Service
SecureAuth [144] SecureAuth Corp.IdP, IdM, Multi-Protocol STS (multiple claims based integrations including SAML 1.1, 2.0 SP SSO, 2.0 IdP SSO, OpenID, .NET, CA SiteMinder and others
SSOCircle [145] SSOCircleFree IdP
Testshib [146] Internet2 IdP and SP for testing
UnitedID [147] United ID ServicesFree IDP service
Verizon Web Access Management [148] Verizon Business IdP
ZXID [149] zxid.orgFree IdP

Related Research Articles

<span class="mw-page-title-main">Single sign-on</span> Authentication scheme

Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single SSO ID to any of several related, yet independent, software systems.

Identity and access management, sometimes also referred to as just Identity management (IdM), is a framework of policies and technologies to ensure that the right users have the appropriate access to technology resources. IAM systems fall under the overarching umbrellas of IT security and data management. Identity and access management systems not only identify, authenticate, and control access for individuals who will be utilizing IT resources but also the hardware and applications employees need to access.

<span class="mw-page-title-main">Liberty Alliance</span> Computer trade group

The Liberty Alliance Project was an organization formed in September 2001 to establish standards, guidelines and best practices for identity management in computer systems. It grew to more than 150 organizations, including technology vendors, consumer-facing companies, educational organizations and governments. It released frameworks for federation, identity assurance, an Identity Governance Framework, and Identity Web Services.

Security Assertion Markup Language is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. SAML is an XML-based markup language for security assertions. SAML is also:

The Central Authentication Service (CAS) is a single sign-on protocol for the web. Its purpose is to permit a user to access multiple applications while providing their credentials only once. It also allows web applications to authenticate users without gaining access to a user's security credentials, such as a password. The name CAS also refers to a software package that implements this protocol.

A federated identity in information technology is the means of linking a person's electronic identity and attributes, stored across multiple distinct identity management systems.

<span class="mw-page-title-main">Shibboleth (software)</span> Internet identity system

Shibboleth is a single sign-on log-in system for computer networks and the Internet. It allows people to sign in using just one identity to various systems run by federations of different organizations or institutions. The federations are often universities or public service organizations.

A credential service provider (CSP) is a trusted entity that issues security tokens or electronic credentials to subscribers. A CSP forms part of an authentication system, most typically identified as a separate entity in a Federated authentication system. A CSP may be an independent third party, or may issue credentials for its own use. The term CSP is used frequently in the context of the US government's eGov and e-authentication initiatives. An example of a CSP would be an online site whose primary purpose may be, for example, internet banking - but whose users may be subsequently authenticated to other sites, applications or services without further action on their part.

Security Assertion Markup Language (SAML) is an XML standard for exchanging authentication and authorization data between security domains. SAML is a product of the OASIS (organization) Security Services Technical Committee.

Security Assertion Markup Language 2.0 (SAML 2.0) is a version of the SAML standard for exchanging authentication and authorization identities between security domains. SAML 2.0 is an XML-based protocol that uses security tokens containing assertions to pass information about a principal between a SAML authority, named an Identity Provider, and a SAML consumer, named a Service Provider. SAML 2.0 enables web-based, cross-domain single sign-on (SSO), which helps reduce the administrative overhead of distributing multiple authentication tokens to the user. SAML 2.0 was ratified as an OASIS Standard in March 2005, replacing SAML 1.1. The critical aspects of SAML 2.0 are covered in detail in the official documents SAMLCore, SAMLBind, SAMLProf, and SAMLMeta.

Web Single Sign-On Interoperability Profile is a Web Services and Federated identity specification, published by Microsoft and Sun Microsystems that defines interoperability between WS-Federation and the Liberty Alliance protocols.

Web Single Sign-On Metadata Exchange Protocol is a Web Services and Federated identity specification, published by Microsoft and Sun Microsystems that defines mechanisms for a service to query an identity provider for metadata concerning the protocol suites it supports. The goal of this operation is to increase the ability of a given service to interoperate with a given identity provider.

<span class="mw-page-title-main">OpenAM</span>

OpenAM is an open-source access management, entitlements and federation server platform. Now it is supported by Open Identity Platform Community.

An identity provider is a system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network. Identity providers offer user authentication as a service. Relying party applications, such as web applications, outsource the user authentication step to a trusted identity provider. Such a relying party application is said to be federated, that is, it consumes federated identity.

WS-Security is a flexible and feature-rich extension to SOAP to apply security to web services. It is a member of the WS-* family of web service specifications and was published by OASIS. Closely related to WS-Security is WS-Trust, also a WS-* specification and OASIS standard that provides extensions to WS-Security.

User-Managed Access (UMA) is an OAuth-based access management protocol standard for party-to-party authorization. Version 1.0 of the standard was approved by the Kantara Initiative on March 23, 2015.

OpenAthens is an identity and access management service, supplied by Jisc, a British not-for-profit information technology services company. Identity provider (IdP) organisations can keep usernames in the cloud, locally or both. Integration with ADFS, LDAP or SAML is supported.

The SAML metadata standard belongs to the family of XML-based standards known as the Security Assertion Markup Language (SAML) published by OASIS in 2005. A SAML metadata document describes a SAML deployment such as a SAML identity provider or a SAML service provider. Deployments share metadata to establish a baseline of trust and interoperability.

A SAML identity provider is a system entity that issues authentication assertions in conjunction with a single sign-on (SSO) profile of the Security Assertion Markup Language (SAML).

References

  1. "Kantara Initiative 2011 Q1 SAML 2.0 Full-Matrix Interoperability Testing".
  2. "Liberty Alliance SAML interoperability tests". 12 November 2021.
  3. "10Duke Identity Provider". 11 February 2022.
  4. "adAS SSO".
  5. "Open Source Identity & Access Management". Aerobase. Retrieved 2024-08-17.
  6. "Aerobase". Aerobase Org.
  7. "Afrilas".
  8. "Asimba".
  9. "AssureBridge".
  10. "Auth0". Auth0. Retrieved 2019-12-12.
  11. "Authentic2".
  12. "Authstack - Identity Access Management (IAM) and Single Sign-On Software". www.buckhill.co.uk. Retrieved 2017-05-15.
  13. "Bitium Single Sign-on".
  14. "CA Federation Manager".
  15. "CAS SAML2 Authentication".
  16. "Secure IT Infrastructure for Online Business Applications | Ceptor". Ceptor. Retrieved 2018-02-26.
  17. "cidaas – European Cloud Identity and Access Management". cidaas. Retrieved 2020-11-21.
  18. "Citrix Open Cloud Access".
  19. "RadiantOne Cloud Federation Service".
  20. "Cloudseal SSO for Java".
  21. "Amazon Cognito: SAML identity providers (identity pools)".
  22. "Comfact IDP".
  23. "Signicat".
  24. "Morpho DACS" (PDF).
  25. "Dot Net Workflow cloud and corporate SSO and Federation".
  26. "DirX Access". Archived from the original on 2011-07-18. Retrieved 2011-07-03.
  27. "DualShield unified authentication platform".
  28. "9STAR's Elastic SSO Team". 16 October 2018.
  29. "9STAR's Elastic SSO Enterprise". 16 October 2018.
  30. "Entrust GetAccess".
  31. "Entrust IdentityGuard".
  32. "EIC".
  33. "EmpowerID".
  34. "API Security Gateway".
  35. "FusionAuth Community Edition".
  36. "GlobalSign SSO". Globalsign. 30 March 2020.
  37. "Open Source Access Management".
  38. "IAM Solutions".
  39. "Horizon App Manager".
  40. "HP IceWall SSO".
  41. "ILANTUS Xpress Sign-On". 10 September 2019.
  42. "Intel Cloud SSO".
  43. "Ilex".
  44. "Avoco Identity".
  45. "iWelcome".
  46. "JOSSO (Community Edition)".
  47. "JOSSO (Enterprise Edition)".
  48. "Juniper SSL VPN" (PDF).
  49. "Keycloak". JBoss Community.
  50. "Layer 7".
  51. "Larpe".
  52. "LemonLDAP::NG".
  53. "NetIQ Access Manager".
  54. "NetWeaver Appserver".
  55. "Mobilityguard OneGate". mobilityguard.com. Retrieved 2016-02-20.
  56. "ForgeRock has shuttered the open-source community, and no longer allows new development on their platform under a permissive license". timeforafork. June 1, 2017. Retrieved June 1, 2017.
  57. "Cloud service platform".
  58. "OneLogin Single Sign On".
  59. "OpenAthens LA".
  60. "OpenAthens SP".
  61. "OpenASelect".
  62. "Optimal IdM VIS Federation Services".
  63. "Oracle Identity Federation 11g".
  64. "Pega7". 15 September 2020.
  65. "PhoneFactor".
  66. "PicketLink".
  67. "PingFederate".
  68. "Plurilock AI Cloud".
  69. "DEFEND Continuous Authentication".
  70. "PortalGuard".
  71. "RSA Federated Identity Manager".
  72. "Safewhere*Identify".
  73. "SailPoint IdentityNow".
  74. "Samanage".
  75. "Github/SATOSA". GitHub . 25 October 2021.
  76. "SecureAuth".
  77. "SurePassID".
  78. "SimpleSAMLphp".
  79. "Smartsignin Single Sign-on".
  80. "SMS PASSCODE".
  81. "SSO EasyConnect".
  82. "Symlabs Federated Identity Suite".
  83. "Symplified".
  84. "Tivoli Federated Identity Manager". 9 November 2020. Archived from the original on November 15, 2013.
  85. "TrustBind/Federation Manager".
  86. "TrustBuilder".
  87. "Trustelem Cloud SSO | Active Directory and multi-factor authentication". www.trustelem.com. Retrieved 2017-05-15.
  88. "USP Secure Entry Server".
  89. "WSO2".
  90. "ZITADEL".
  91. "ZXID".
  92. "Federation Registry".
  93. "ComponentSpace".
  94. "cortoweb".
  95. "knaperek/djangosaml2". GitHub. Retrieved 2016-06-08.
  96. "EmpowerID Dot Net Workflow Idp & SP Kit".
  97. "Federation Metadata Manager for ADFS".
  98. "Firefox ECP Plugin".
  99. "FLOG". GitHub . 8 May 2020.
  100. "JAGGER (ResourceRegistry3". GitHub . 20 October 2021.
  101. "JAKOB Attribute Collector".
  102. "JANUS". GitHub . 21 March 2020.
  103. "Jitbit SAML toolkil". GitHub . 13 April 2022.
  104. "Lasso".
  105. "LightSAML core".
  106. "OIOSAML 2.0 Toolkit".
  107. "OIOSAM.net Service Provider Framework" (PDF).
  108. "Shibboleth Binding for OmniAuth 1.x". GitHub . 16 December 2020.
  109. "SAML Toolkits from OneLogin".
  110. "OpenConext".
  111. "OpenSAML".
  112. "Metadata Explorer Tool". GitHub . 14 January 2021.
  113. "Mujina Mock IdP and SP". GitHub . 13 April 2022.
  114. "PAC4J Security Engine".
  115. "PEER". GitHub . 26 June 2018.
  116. "PHPH". GitHub . 7 June 2015.
  117. "PingFederate Integration Kits".
  118. "PySAML2". GitHub . 13 April 2022.
  119. "Pysfemma". GitHub . 28 January 2019.
  120. "PyFF".
  121. "Raptor".
  122. "SAML Metadata Aggregator".
  123. "SAML Tracer".
  124. "SAMLBlackbox (SAML component and class library) - SecureBlackbox". www.secureblackbox.com. Retrieved 2019-02-20.
  125. "SpringSecurity SAML Site".
  126. "SWITCH Group Management Tool".
  127. https://wiki.edugain.org/Webisoget
  128. "ZXID".
  129. "9STAR Shibboleth/SAML SSO Services". 23 October 2018.
  130. "9STAR Shibboleth/SAML SSO Support". 16 October 2018.
  131. "Arcot A-OK".
  132. "eduTEAMs".
  133. "Federation Lab".
  134. "Feide OpenIdP".
  135. "Gazelle IHE interop test framework".
  136. "Gluu On-Prem Managed Service".
  137. "Identity Hub".
  138. "OneLogin SSO".
  139. "RE:EP".
  140. "Phonefactor".
  141. "PingOne".
  142. "SAML .NET Dev Zone".
  143. "samlidp.io - SAML Identity Provider as a Service". samlidp.io. Retrieved 2017-03-21.
  144. "SecureAuth Corp".
  145. "SSO Circle IDP".
  146. "Testshib.org".
  147. "United ID".
  148. "Verizon Web Access Management as a Service".
  149. "ZXIDP.org".