Single Sign-On плагин для Sonatype Nexus Repository

Хочу рассказать о своём проекте - Single Sign-On плагин для Sonatype Nexus Repository . Плагин реализует аутентификацию через SSO и пользовательские токены для Nexus редакции "Community Edition". Если вам интересна эта тема, то добро пожаловать под кат.

https://habr.com/ru/articles/904766/

#сезон_open_source #sonatype_nexus_repository_oss #sso #saml #java #osgi #хранение_данных

Single Sign-On плагин для Sonatype Nexus Repository

Привет, Хабр! Сегодня я хочу рассказать о своём проекте - Single Sign-On плагин для Sonatype Nexus Repository . Sonatype Nexus Repository — это репозиторий артефактов, который поддерживает...

Хабр

I became a maintainer of a popular #SAML library for Node.js, "node-saml", which in turn uses "xml-crypto", which in turn is based on XML signatures.

If you are still using SAML for #SSO, be aware there has been string of SAML vulnerabilities related to the fundamentals of how it works and there are likely to be more. You are advised to OIDC instead.

In this thread, I'll discuss some of weaknesses in SAML that have come up repeatedly. 🧵

#infosec #security #coding #programming

Long shot, but: As my project for #eh22 I was thinking about extending our #Keycloak configuration auditor with some checks for #SAML-based authentication. However, I know next to nothing about SAML and am a bit lost, to be honest. If anyone is at #eh22 who has some knowledge about SAML security and common misconfigurations (on the server or client side), and wants to collaborate to create some checks for #kcwarden (https://github.com/iteratec/kcwarden), hit me up.
GitHub - iteratec/kcwarden: Keycloak Configuration Auditor

Keycloak Configuration Auditor. Contribute to iteratec/kcwarden development by creating an account on GitHub.

GitHub
I'm sure there is a simple, totally obvious reason (no trusted central authority problem?) but it seems kind of strange to me that the #Fediverse doesn't allow me to truly use a single login across services via some kind of #FIDO compliant magic, considering that almost everyone is an #infosec person and/or developer. Admittedly, I haven't thought about this too deeply. Also, where's passkey support? #saml #sso

🍋 LemonLDAP::NG 2.21 is out!

📃 This new release includes improvements on OpenID Connect and CAS protocols, Loki logger, public notifications and much more.

🔗 Read our release notes: https://projects.ow2.org/view/lemonldap-ng/lemonldap-ng-2-21-0-is-out/

@ow2 @worteks_com

#IAM #SSO #CAS #SAML #OpenIDConnect #OW2 #lemonldap #lemonldapng #Passkeys #Passwordless #WebAuthn #FIDO2 #Loki #WebSSO #OpenSource #FreeSoftware #LogicielLibre #Perl

OW2 Projects - LemonLDAP::NG 2.21 is out! (lemonldap-ng.lemonldap-ng-2-21-0-is-out.WebHome)

LemonLDAP::NG 2.21 is out!

Learnings am Wegesrand: Für die Signierung und Verschlüsselung von #SAML-Metadaten nutzt man wegen der häufigen Rotationen und fehlender Automatisierungsmöglichkeit bei Kommunikationspartnern ja meist keine Letsencrypt-Zertifikate. Gestern dachte ich, ach für diesen kurzen Test geht’s mal. Und dann habe ich lange nach dem Fehler gesucht und gemerkt, dass Letsencrypt inzwischen EC-Schlüssel statt RSA generiert,mit denen der #Shibboleth SP nicht signieren kann. #til #sso #singlesignon
These SAMLStorm vulnerabilities have been public for a couple weeks now. Anyone seeing exploitation in the wild? How’s patching going across vendors and infra? #infosec #SAML #NodeJS #AppSec
Du verwendest #SAML #Authentifizierung?
Die letzten #Mastodon #Releases enthalten wichtige Sicherheitsupdates.
https://github.com/mastodon/mastodon/releases
Releases · mastodon/mastodon

Your self-hosted, globally interconnected microblogging community - mastodon/mastodon

GitHub

Hivemind:

Roll your own SAML (like, no IdP)?

#appsec #infosec #SAML

Just fine.
6.7%
Scary.
20%
Never ever.
10%
Run like the wind.
63.3%
Poll ended at .

 GitHub uncovers new Ruby-SAML Vulnerabilities allowing Account Takeover Attacks.

Two high-severity security flaws have been disclosed in the open-source ruby-saml library that could allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication protections.

https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/

#github #ruby #saml #library #it #security #privacy #engineer #media #programming #tech #news

Sign in as anyone: Bypassing SAML SSO authentication with parser differentials

Critical authentication bypass vulnerabilities were discovered in ruby-saml up to version 1.17.0. See how they were uncovered.

The GitHub Blog