Security Assertion Markup Language (SAML) is a set of specifications that encompasses the XML-format for security tokens containing assertions to pass information about a user and protocols and profiles to implement authentication and authorization scenarios. This article has a focus on software and services in the category of identity management infrastructure, which enable building Web-SSO solutions using the SAML protocol in an interoperable fashion. Software and services that are only SAML-enabled do not go here.
SAML actors are Identity Providers (IdP), Service Providers (SP), Discovery Services, ECP Clients, Metadata Services, or Broker/IdP-proxy. This table shows the capability of products according to Kantara Initiative testing. [1] [2] Claimed capabilities are in column "other". Each mark denotes that at least one interoperability test was passed. Detailed results with product and test procedure versions are available at the Kantara/Liberty site given below.
NOTE: This table represents a snapshot over time roll up of the most recent product test results (multiple testing rounds). Please note that some products features and abilities may have been updated since they were last tested. Please check the website information of the originating product for the latest features and updates.
Product Name | Project/Vendor | License | Kantara-certified Interoperability | Other Features | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
IdP | IdP Light | SP | SP Light | eGov 1.5 | Attr Auth Resp | POST Bind. | Roles | Protocols | |||||||||
Broker | Discovery | ECP | IdP | IdP Proxy | Reverse Proxy | SP | |||||||||||
10Duke Identity Provider [3] | 10Duke | Commercial | SAML 1.1, SAML 2.0, OAuth 2, OpenID, LDAP, Federation | ||||||||||||||
adAS SSO [4] | PRiSE | OSS | SAML 2.0, SAML 1.0, Google, Microsoft365, Facebook, Twitter, Kerberos, LDAP, Federation, OAuth2, OpenID Connect, CAS v1, CAS v2, PAPI, OpenID | ||||||||||||||
ADFS 1.x | Microsoft | Commercial | WS-Federation, WS-Trust, SAML 1.0 | ||||||||||||||
ADFS 2.0 | Microsoft | Commercial | WS-Federation, WS-Trust, SAML 1.1/2.0 | ||||||||||||||
ADFS 2.1 | Microsoft | Commercial | WS-Federation, WS-Trust, SAML 2.0 | ||||||||||||||
ADFS 3.0 | Microsoft | Commercial | WS-Federation, WS-Trust, SAML 2.0, OAuth2 | ||||||||||||||
ADFS 4.0 | Microsoft | Commercial | WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect | ||||||||||||||
Aerobase [5] | Aerobase | OSS | Integrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications [6] | ||||||||||||||
Afrilas [7] | Able - AXS Guard | Commercial | SAML 2.0 Strong Authentication without usernames | ||||||||||||||
Asimba [8] | Asimba.org | OSS | (Fork of OpenASelect) | ||||||||||||||
AssureBridge SAMLConnect [9] | AssureBridge | Commercial | SAML 1.1, SAML 2.0, OpenID, WS-Federation, Kerberos, Radius, X509, LDAP | ||||||||||||||
Auth0 [10] | Auth0 | Commercial | OAuth2, OpenID, SAML 1.1, SAML 2.0, WS-Federation, LDAP | ||||||||||||||
Authentic2 [11] | Entrouvert | OSS | OpenID 1&2, CAS 1&2, OAuth2, LDAP 2&3, PAM, RADIUS, OATH, Kerberos, X509 | ||||||||||||||
AuthStack [12] | Buckhill | Commercial | SAML 1.0, SAML 1.1, SAML 2.0, LDAP, Kerberos, X509, RADIUS, OAuth2, SOAP/REST API | ||||||||||||||
BIG-IP Access Policy Manager | F5 Networks | Commercial | SAML 2.0 | ||||||||||||||
Bitium [13] | Bitium | Commercial | SAML, SAML 2.0 | ||||||||||||||
CA Single Sign-On [14] | CA | Commercial | SAML 1.0/1/1/2.0, OAuth2, OpenID, WS-Federation | ||||||||||||||
Central Authentication Server (CAS) [15] | Apereo Foundation | Open source | SAML 2.0, OAuth2, OpenID, WS-Federation | ||||||||||||||
Centrify DirectControl | Centrify | Commercial | SAML, OpenID, OAuth, WS-*, LDAP, Kerberos | ||||||||||||||
Ceptor [16] | Ceptor | Commercial | SAML 1.1/2.0, OAuth 2.0, WS-Federation, OpenID Connect, Kerberos | ||||||||||||||
cidaas [17] | cidaas by Widas ID GmbH | Commercial | SAML 2.0, OAuth2, OpenID Connect | ||||||||||||||
Citrix Open Cloud [18] | Citrix | Commercial | SSO Middleware, native service connectors | ||||||||||||||
Cloud Identity Manager | McAfee | Commercial | SAML 2, OpenID, OAuth, XACML, LDAP v3, JM | ||||||||||||||
Cloud Federation Service [19] | Radiant Logic | Commercial | SAML 2.0, WS-Federation, OAuth 2.0, OpenID | ||||||||||||||
Cloudseal [20] | Cloudseal | SaaS | |||||||||||||||
Cognito [21] | Amazon | Commercial | SAML 2.0 | ||||||||||||||
Comfact IDP [22] | Comfact | Commercial | |||||||||||||||
Signicat [23] | Signicat | Commercial | |||||||||||||||
Corto project home | GÉANT | OSS | |||||||||||||||
DACS [24] | Safran Identity & Security | Commercial | SSO, OpenID Connect, OATH & OCRA, SMS, X509v3 Certificate, eID card, FIDO UAF, LDAP/AD, multi-factor | ||||||||||||||
Dot Net Workflow [25] | The Dot Net Factory | Commercial | WS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN) | ||||||||||||||
DirX Access [26] | Atos/Siemens | Commercial | |||||||||||||||
DualShield [27] | Deepnet Security | Commercial | SAML 2.0 | ||||||||||||||
Elastic SSO Team [28] | 9STAR | Commercial | SAML 2.0 SAML 1.1 | ||||||||||||||
Elastic SSO Enterprise [29] | 9STAR | Commercial | SAML 2.0 SAML 1.1 | ||||||||||||||
ESOE | Queensland University of Technology | OSS | |||||||||||||||
Entra ID (formerly known as Azure Active Directory) | Microsoft | Commercial | SAML 2.0, WS-Federation, Kerberos Constrained Delegation, OAuth 2.0, OpenID Connect | ||||||||||||||
Entrust GetAccess [30] | Entrust | Commercial | SAML 1.0, SAML 1.1, SAML 2.0 | ||||||||||||||
Entrust IdentityGuard [31] | Entrust | Commercial | SAML 2.0, OpenID | ||||||||||||||
EIC [32] | Ericsson | Commercial | |||||||||||||||
EmpowerID [33] | The Dot Net Factory | Commercial | WS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN) | ||||||||||||||
Evidian Web Access Manager | Evidian | Commercial | SAML 1.1, SAML 2.0, OpenID Connect, CAS 1&2, OAuth2, LDAP v3, RADIUS, OATH, Kerberos, X509, Microsoft365, Google, Multi-factor, SSO, extended integration functionalities, Federation | ||||||||||||||
Fluig Identity | TOTVS | Commercial | SAML 2.0 | ||||||||||||||
Forum Sentry [34] | Forum Systems | Commercial | WS-Federation, WS-Trust, SAML 2.0, SAML 1.1, OAuth 1.0.a. OAuth 2, OpenID Connect | ||||||||||||||
Fugen Cloud ID Broker | Fugen Solutions | Commercial | SAML 1.1, SAML 2.0, WS-Federation, WS-Trust, OpenID, and OAuth | ||||||||||||||
FusionAuth [35] | FusionAuth | Commercial | SAML 2.0, OIDC, OAuth, LDAP | ||||||||||||||
GlobalSign SSO | GMO GlobalSign | Commercial | SAML 2.0, ETSI MSS 102 204, TUPAS, WS-Federation, OpenID | ||||||||||||||
Gluu Server [37] | Gluu | OSS | OpenID Connect, UMA, RADIUS, LDAP, FIDO, OAuth | ||||||||||||||
Hitachi ID Identity and Access Management Suite [38] | Hitachi ID Systems, Inc. | Commercial | SAML 2.0 | ||||||||||||||
Horizon App Manager [39] | VMware | Commercial | ? | ||||||||||||||
HP IceWall SSO [40] | HP | Commercial | SAML 2 | ||||||||||||||
ILANTUS Sign On Express [41] | Ilantus | Commercial | SAML 2 | ||||||||||||||
Intel Cloud SSO [42] | Intel | Commercial | SAML 2, OpenID, OAuth | ||||||||||||||
Ilex Sign&go [43] | ILEX | Commercial | WS-Federation, WS-Trust, SAML 2.0, SAML 1.0, Shibboleth, CAS, Google, Microsoft365, Facebook, Kerberos, LDAP | ||||||||||||||
iSAML [44] | Avoco | Commercial | SAML 2, WS-Trust, OpenID | ||||||||||||||
iWelcome [45] | iWelcome | Commercial | SAML 2, SAML 1.0, WS-Trust, Kerberos, OAuth2, Facebook, google, includes provisioning from-to on-Prem, AD, Multi-factor, extended integration functionalities | ||||||||||||||
JOSSO (Community Ed.) [46] | josso.org | OSS | SAML2, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1 | ||||||||||||||
JOSSO (Enterprise Ed.) [47] | Atricore | Commercial | SAML2, WS-Fed, OpenID Connect, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1 | ||||||||||||||
Juniper SSL VPN [48] | Juniper Networks | Commercial | |||||||||||||||
Keycloak | JBoss | OSS | Integrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications [49] | ||||||||||||||
Layer 7 [50] | SecureSpan Gateway | Commercial | PDP/PEP, Auth2, SAML 1.1, SAML2, ABAC, OpenID Connect, XML Firewall | ||||||||||||||
Larpe [51] | Entrouvert | OSS | SAML, OpenID, CAS, OAuth | ||||||||||||||
LemonLDAP::NG [52] | LemonLDAP::NG | OSS | SSO, WS-Federation, CAS, OpenID-Connect, SAML-2, Twitter, Protocol proxy | ||||||||||||||
LoginRadius | LoginRadius | Commercial | Web SSO, Federation SSO, SAML, OAuth, OIDC, WS-Federation, JWT | ||||||||||||||
MicroFocus (NetIQ) Access Manager [53] | NetIQ (formerly Novell) | Commercial | + SP Broker | WS-Security, WS-Federation, WS-Trust, SAML 1.1 / 2.0, Liberty, Single Sign-on, RBAC, CardSpace, OAuth 2.0, OpenID, STS. Includes out of the box integration with cloud and social media providers (Office 365, Windows Live (MSN), Google, Facebook, Salesforce, Amazon web services and 200+ preconfigured connections to SaaS providers etc.) Integration for Advanced Authentication Framework | |||||||||||||
miniOrange | miniOrange | Commercial | + Identity Broker | SAML 2.0, OAuth2, OpenID Connect, WS-Fed | |||||||||||||
NetWeaver Appserver [54] | SAP | Commercial | ? | CAS, OpenId, Twitter | |||||||||||||
OneGate [55] | MobilityGuard | Commercial | SAML 1.1, SAML 2.0 | ||||||||||||||
OpenAM | Open Identity Community , ForgeRock (ex. Sun) until 2016 [56] | CDDL | OpenID Connect, OAuth2, SAML 2.0, SAML 1.1, WS-Federation, WS-Trust, XACML, Liberty, Kerberos, Facebook, Google, Windows Live (MSN) | ||||||||||||||
Okta [57] | Okta | Commercial | WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect | ||||||||||||||
OneLogin [58] | OneLogin | Commercial | SAML, WS-Federation, Kerberos, OAuth, OpenID | ||||||||||||||
OpenAthens LA [59] | eduserv | Commercial | |||||||||||||||
OpenAthens SP [60] | eduserv | Commercial | |||||||||||||||
Open Select [61] | OpenASelect.org | OSS | OAuth (project continues as asimba) | ||||||||||||||
Optimal IdM VIS Federation Services [62] | Optimal IdM | Commercial | + Proxy, SSO | WS-Federation, WS-Trust, SAML 1.x, SAML 2.0, OAuth2, OpenID Connect, SCIM, Facebook, Twitter, LinkedIn, Google, IWA, X509, Kerberos, LDAP, Office 365, RADIUS, MFA (Push, SMS, Email, Voice, TOTP, U2F, Radius) | |||||||||||||
Oracle Identity Federation 11g [63] | Oracle | Commercial | WS-Federation, SAML 1.x, SAML 2.0, OpenID 2.0 | ||||||||||||||
Pega 7 Platform [64] | Pegasystems Inc. | Commercial | SAML 2.0, OAuth, WS-Trust, LDAP | ||||||||||||||
PhoneFactor [65] | PhoneFactor, Inc | Commercial | |||||||||||||||
PicketLink [66] | JBoss Community | OSS | OpenID, A-Select, CAS, XACML | ||||||||||||||
PingFederate [67] | Ping Identity | Commercial | SAML 1.1, SAML 2.0, WS-Federation, WS-Trust, WS-Security, OAuth, OpenID Connect, OpenID, SCIM, Facebook, Twitter, LinkedIn, Google, Windows Live, Kerberos, IWA, X.509, LDAP, RADIUS, 3rd Party MFA | ||||||||||||||
Plurilock AI [68] | Plurilock | Commercial | SAML 1.1, SAML 2.0, FIDO2, OTP, DEFEND [69] | ||||||||||||||
PortalGuard [70] | PistolStar, Inc. | Commercial | SAML 2, LDAP v3, XML-DSIG, SSO Middleware | ||||||||||||||
RSA Federated Identity [71] | RSA | Commercial | Facebook, OpenID, LinkedIn, Twitter, Windows Live | ||||||||||||||
SAASPASS | SAASPASS | Commercial | WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, LDAP | ||||||||||||||
Safewhere*Identify [72] | Safewhere | Commercial | SAML 2.0, WS-Federation, WS-Trust, OAuth 2.0, multi-factor, OpenID Connect, Facebook, LinkedIn, Twitter, LiveID, Google, LDAP | ||||||||||||||
SailPoint IdentityNow [73] | SailPoint | Commercial | SAML 1.1, SAML 2.0, OAuth2, Kerberos, WS-Federation | ||||||||||||||
Samanage [74] | Samanage | Commercial | Enterprise-to-cloud SSO Middleware | ||||||||||||||
SATOSA [75] | SATOSA | OSS | Proxy between SAML2, OpenID Connect and OAuth2 | ||||||||||||||
SecureAuth [76] | SecureAuth Corp. | Commercial | 2-Factor, IBM LTPA, Facebook, Google, LinkedIn, Microsoft FBA, Microsoft IWA, OAUTH, OpenID, OpenID Connect, SAML 1.1, SAML 2.0, Twitter, WebServices, Windows Live, X.509v3, Yahoo | ||||||||||||||
SecureSSO [77] | SurePassID | Commercial | WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, O365, SCADA - cloud & on-prem | ||||||||||||||
Shibboleth | Internet2 | OSS | SAML 1.1, SAML 2.0 | ||||||||||||||
SimpleSAMLphp [78] | UNINETT AS | OSS | OpenID, A-Select, CAS, WS-Federation and OAuth, Facebook, LinkedIn, Twitter, Windows Live, SAML 2 | ||||||||||||||
Smartsignin [79] | PerfectCloud | Commercial | SAML 2.0, SAML 1.0, Google, Microsoft365, LDAP, WS-Federation | ||||||||||||||
SMS PASSCODE Multi-factor Authentication [80] | SMS PASSCODE | Commercial | ? | ||||||||||||||
SSO EasyConnect [81] | SSO Easy | Commercial | |||||||||||||||
SSOgen | SSOGEN Corporation | Commercial | SAML 1.1, SAML 2.0, OAuth2, OpenID Connect, OpenID Provider, RADIUS, LDAP, Multi Factor Authentication. Cloud SSO Solution for enterprises to protect on-premise applications such as SSOgen for Oracle EBS, SSOgen for PeopleSoft, SSOgen for JDE, and SSOgen for SAP, with a web server plug-in and Cloud SaaS applications with SAML, OpenID Connect integrations. | ||||||||||||||
Symlabs Federated Identity Suite [82] | Symlabs | Commercial | OpenID, A-Select, CAS, WS-Federation and OAuth | ||||||||||||||
Symplified [83] | Symplified | Commercial | SAML 1.1, SAML 2.0, WS-Federation, OpenID, OAuth, XACML, IBM LTPA, Microsoft IWA, 2-Factor, Facebook, Google, Twitter, ABAC / context-based AC | ||||||||||||||
Tivoli Federated Identity Manager [84] | IBM | Commercial | WS-Federation, OpenID, Liberty, InfoCard, Microsoft CardSpace | ||||||||||||||
TrustBind [85] | NTT Software Corp | Commercial | OpenID, ID-WSF | ||||||||||||||
TrustBuilder [86] | SecurIT | Commercial | SAML 2.0, OAuth 2.0, OpenID Connect, Kerberos | ||||||||||||||
Trustelem [87] | Trustelem | Commercial | SAML 2.0, OpenID Connect, WS-Fed, OAuth 2.0, Integrated Windows Authentication, Kerberos, Active Directory, LDAP, FIDO U2F. | ||||||||||||||
USP Secure Entry Server [88] | United Security Providers | Commercial | SAML 2.0, SAML 1.0, Kerberos, NTLM, LDAP, RADIUS, RSA, SuisseID, RBAC, SSO, Tomcat Authenticator, IIS ISAPI Filter, mTAN, PKI/X.509, Reverse Proxy, Multi-Factor, SOAP/REST Connectors, WebService Security, Office365, GoogleApps | ||||||||||||||
Weblogic | Oracle | Commercial | |||||||||||||||
WSO2 [89] | wso2 | OSS | OAuth2, WS-Trust, OpenID | ||||||||||||||
ZITADEL [90] | ZITADEL | OSS | SAML 2.0, OpenID Connect 1.0, OAuth 2.0, FIDO2, OTP, U2F | ||||||||||||||
ZXID [91] | zxid | OSS | ID-WSF2, XACML2, WS-Security, XML-DSIG, TAS3 |
Libraries and toolkits are used by developers to integrate applications and services into SAML federations or to build their own SAML-actors like IdPs.
Libraries and Toolkits | Organization | Licence | Purpose and Language bindings |
---|---|---|---|
Australian Access Federation [92] | Australian Access Federation | OSS | Metadata Registry based on former work by SWITCH |
ComponentSpace [93] | ComponentSpace | Commercial | SAML libraries for ASP.NET and ASP.NET Core applications |
Corto [94] | WAYF | OSS | SAML2 proxy, virtual IdP, user consent |
DjangoSAML2 [95] | GitHub | OSS | SAML2 application for Django, using PySAML2 underneath |
EmpowerID IdP & SP Kit [96] | Dot Net Factory | Commercial | IdP and SP Kit, .NET, REST, and SOAP-based integration kit to SAML-enable applications |
FEMMA [97] | SourceForge | OSS | Workaround for the ADFS limitation of a single EntityID per XML infoset |
Firefox ECP Plugin [98] | Openliberty | OSS | Firefox extension for compliance with SAML ECP |
FLOG F-Ticks Vizualization [99] | SUNET | OSS | Parse and chart F-Ticks for webSSO and Eduroam (sample site: http://flog.sunet.se/) |
Jagger [100] | HEAnet | OSS | Metadata and Federation data manager; Shibboleth IDP GUI |
JAKOB [101] | WAYF | OSS | Backchannel attribute collector |
JANUS [102] | WAYF | OSS | Metadata Registry for hub-and-spoke federations based on SimpleSAMLphp; includes self-service |
Jitbit ASP.NET SAML lib [103] | GitHub | OSS | SAML 2.0 "consumer" component for ASP.NET |
Lasso [104] | Entrouvert | OSS | SAML-Library: C/C++, Python, Java, Perl, PHP |
LightSAML core [105] | OSS | SAML-Library: PHP | |
OIOSAML 2.0 Toolkit [106] | Danish IT and Telekom Agency | OSS | SP Framework: Java, .NET, [107] PHP (Documentation see OIOSAML.java) |
OmniAuth-Shibboleth [108] | OneLogin | OSS | SAML-Library: ASP/.NET, Java, PHP, Python, Ruby |
OneLogin [109] | OneLogin | OSS | SAML-Library: ASP/.NET, Java, PHP, Python, Ruby |
OpenConext [110] | SURFnet | OSS | Service Provider Proxy and Hub-and-Spoke federation middleware, includes SAML proxy and central group management for creating collaboration platforms |
OpenSAML [111] | Internet2 | OSS | SAML-Library: C++, Java |
MET [112] | TERENA | OSS | gathers and shows information about federations (mostly about SPs and IdPs) |
Mujina [113] | SURFnet | OSS | SAML test actors that can be dynamically configured using a REST interface |
PAC4J-SAML [114] | OSS | SAML Service Provider Library (and other authentication mechanisms) | |
PEER [115] | GÉANT | OSS | SAML Metadata Registry |
PHPH [116] | WAYF.dk | OSS | SAML Metadata Processor |
Ping Identity [117] | Ping Identity | Commercial | Java, .NET, PHP and language neutral integration kits to SAML-enable applications |
PySAML2 [118] | GitHub | OSS | SAML-Library: Python |
Python-SAML | OneLogin | OSS | SAML-Library: Python |
Pysfemma [119] | GitHub | OSS | automate membership configuration of an ADFS STS in a SAML2 based Identity Federation |
PyFF [120] | SUNET | OSS | SAML Metadata Processor |
Raptor [121] | Jisc | OSS | toolkit to enable Shibboleth IdP statistics analysis |
SAML Metadata Aggregator [122] | NORDUnet | OSS | Aggregates single metadata files and provides MDX webservice |
SAML Tracer (Firefox addon) [123] | UNINETT AS | OSS | Firefox Plug-In to trace SAML messages |
SecureBlackbox [124] | /n software | Commercial | The component that implements SAML in client apps, which need to use service providers, or can be used to create your own service and identity providers |
SpringSecurity SAML [125] | SpringSource | OSS | SAML-enable applications based on Spring framework |
Switch GMT [126] | SWITCH-AAI | OSS | Group Management Tool for Shibboleth |
Webisoget [127] | OSS | Command-line Tool to fetch a SSO-protected page including Shibboleth-Login | |
ZXID [128] | zxid | OSS | C, other lang using swig.org |
This section lists public services such as identity and attribute providers, metadata and test services, but *not* SAML-enabled web-applications and cloud services.
Service | Organization | Purpose |
---|---|---|
9STAR [129] | 9STAR | 9STAR Managed Services for Shibboleth/SAML SSO On-Premises or Cloud |
9STAR [130] | 9STAR | 9STAR Shibboleth/SAML SSO Support Services |
Acrot A-OK [131] | Arcot | IdP (+ Fraud detection) |
eduTEAMs [132] | SURFnet | Federation enabled Group management service which acts as an Attribute Authority for group relations |
Federation Lab [133] | GÉANT | Test-SP, metadata registry, test tools |
Feide OpenIdP [134] | UNINETT AS | IdP that allows any user to register, and any SP to connect |
Gazelle IHE validator [135] | Gazelle | SAML Assertion Validation |
Gluu On-Prem Managed Service [136] | Gluu | IdP for SAML and OpenID Connect-enabled cloud services |
Identity Hub [137] | Entrouvert | Free IdP; Any user and any SP |
OneLogin SSO [138] | OneLogin | IdP for SAML- and OpenID-enabled cloud services |
REEP [139] | GÉANT | Public metadata registry |
PhoneFactor [140] | PhoneFactor Inc. | IdP/cloud SSO |
PingOne [141] | Ping Identity | Cloud Access and Application Provider Services for IdPs and SPs |
SAASPASS | SAASPASS | IdP, IdM, Multi-Protocol STS (multiple claims based integrations including SAML 1.1, 2.0 SP SSO, 2.0 IdP SSO, OpenID Connect, .NET, CA SiteMinder and others |
SamlComponent.net [142] | SamlComponent | SAML Resources for Developers |
samlidp.io [143] | Kitek Media Kft. | SAML Identity Provider as a Service |
SecureAuth [144] | SecureAuth Corp. | IdP, IdM, Multi-Protocol STS (multiple claims based integrations including SAML 1.1, 2.0 SP SSO, 2.0 IdP SSO, OpenID, .NET, CA SiteMinder and others |
SSOCircle [145] | SSOCircle | Free IdP |
Testshib [146] | Internet2 | IdP and SP for testing |
UnitedID [147] | United ID Services | Free IDP service |
Verizon Web Access Management [148] | Verizon Business | IdP |
ZXID [149] | zxid.org | Free IdP |
Single sign-on (SSO) is an authentication scheme that allows a user to log in with a single SSO ID to any of several related, yet independent, software systems.
Identity and access management, sometimes also referred to as just Identity management (IdM), is a framework of policies and technologies to ensure that the right users have the appropriate access to technology resources. IAM systems fall under the overarching umbrellas of IT security and data management. Identity and access management systems not only identify, authenticate, and control access for individuals who will be utilizing IT resources but also the hardware and applications employees need to access.
The Liberty Alliance Project was an organization formed in September 2001 to establish standards, guidelines and best practices for identity management in computer systems. It grew to more than 150 organizations, including technology vendors, consumer-facing companies, educational organizations and governments. It released frameworks for federation, identity assurance, an Identity Governance Framework, and Identity Web Services.
Security Assertion Markup Language is an open standard for exchanging authentication and authorization data between parties, in particular, between an identity provider and a service provider. SAML is an XML-based markup language for security assertions. SAML is also:
The Central Authentication Service (CAS) is a single sign-on protocol for the web. Its purpose is to permit a user to access multiple applications while providing their credentials only once. It also allows web applications to authenticate users without gaining access to a user's security credentials, such as a password. The name CAS also refers to a software package that implements this protocol.
A federated identity in information technology is the means of linking a person's electronic identity and attributes, stored across multiple distinct identity management systems.
Shibboleth is a single sign-on log-in system for computer networks and the Internet. It allows people to sign in using just one identity to various systems run by federations of different organizations or institutions. The federations are often universities or public service organizations.
A credential service provider (CSP) is a trusted entity that issues security tokens or electronic credentials to subscribers. A CSP forms part of an authentication system, most typically identified as a separate entity in a Federated authentication system. A CSP may be an independent third party, or may issue credentials for its own use. The term CSP is used frequently in the context of the US government's eGov and e-authentication initiatives. An example of a CSP would be an online site whose primary purpose may be, for example, internet banking - but whose users may be subsequently authenticated to other sites, applications or services without further action on their part.
Security Assertion Markup Language (SAML) is an XML standard for exchanging authentication and authorization data between security domains. SAML is a product of the OASIS (organization) Security Services Technical Committee.
Security Assertion Markup Language 2.0 (SAML 2.0) is a version of the SAML standard for exchanging authentication and authorization identities between security domains. SAML 2.0 is an XML-based protocol that uses security tokens containing assertions to pass information about a principal between a SAML authority, named an Identity Provider, and a SAML consumer, named a Service Provider. SAML 2.0 enables web-based, cross-domain single sign-on (SSO), which helps reduce the administrative overhead of distributing multiple authentication tokens to the user. SAML 2.0 was ratified as an OASIS Standard in March 2005, replacing SAML 1.1. The critical aspects of SAML 2.0 are covered in detail in the official documents SAMLCore, SAMLBind, SAMLProf, and SAMLMeta.
Web Single Sign-On Interoperability Profile is a Web Services and Federated identity specification, published by Microsoft and Sun Microsystems that defines interoperability between WS-Federation and the Liberty Alliance protocols.
Web Single Sign-On Metadata Exchange Protocol is a Web Services and Federated identity specification, published by Microsoft and Sun Microsystems that defines mechanisms for a service to query an identity provider for metadata concerning the protocol suites it supports. The goal of this operation is to increase the ability of a given service to interoperate with a given identity provider.
OpenAM is an open-source access management, entitlements and federation server platform. Now it is supported by Open Identity Platform Community.
An identity provider is a system entity that creates, maintains, and manages identity information for principals and also provides authentication services to relying applications within a federation or distributed network. Identity providers offer user authentication as a service. Relying party applications, such as web applications, outsource the user authentication step to a trusted identity provider. Such a relying party application is said to be federated, that is, it consumes federated identity.
WS-Security is a flexible and feature-rich extension to SOAP to apply security to web services. It is a member of the WS-* family of web service specifications and was published by OASIS. Closely related to WS-Security is WS-Trust, also a WS-* specification and OASIS standard that provides extensions to WS-Security.
User-Managed Access (UMA) is an OAuth-based access management protocol standard for party-to-party authorization. Version 1.0 of the standard was approved by the Kantara Initiative on March 23, 2015.
OpenAthens is an identity and access management service, supplied by Jisc, a British not-for-profit information technology services company. Identity provider (IdP) organisations can keep usernames in the cloud, locally or both. Integration with ADFS, LDAP or SAML is supported.
The SAML metadata standard belongs to the family of XML-based standards known as the Security Assertion Markup Language (SAML) published by OASIS in 2005. A SAML metadata document describes a SAML deployment such as a SAML identity provider or a SAML service provider. Deployments share metadata to establish a baseline of trust and interoperability.
A SAML identity provider is a system entity that issues authentication assertions in conjunction with a single sign-on (SSO) profile of the Security Assertion Markup Language (SAML).