<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=OASIS_SAML_Security_and_Privacy_2.0</id>
	<title>OASIS SAML Security and Privacy 2.0 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=OASIS_SAML_Security_and_Privacy_2.0"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=OASIS_SAML_Security_and_Privacy_2.0&amp;action=history"/>
	<updated>2026-05-11T05:26:17Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=OASIS_SAML_Security_and_Privacy_2.0&amp;diff=4979&amp;oldid=prev</id>
		<title>Omaerz: 5 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=OASIS_SAML_Security_and_Privacy_2.0&amp;diff=4979&amp;oldid=prev"/>
		<updated>2018-06-28T04:02:25Z</updated>

		<summary type="html">&lt;p&gt;5 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;#039;&amp;#039;&amp;#039;Title&amp;#039;&amp;#039;&amp;#039;: Security and Privacy Considerations for the OASIS Security Assertion Markup Language (SAML) V2.0&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Category&amp;#039;&amp;#039;&amp;#039;: Authentication Procotol Specification&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Date&amp;#039;&amp;#039;&amp;#039;: 3/15/2005&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Creator&amp;#039;&amp;#039;&amp;#039;: OASIS&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;URL&amp;#039;&amp;#039;&amp;#039;: http://docs.oasis-open.org/security/saml/v2.0/saml-sec-consider-2.0-os.pdf&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;	&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Description&amp;#039;&amp;#039;&amp;#039;: Provides security and privacy considerations for users of SAML 2.0, including some specific implementation&lt;br /&gt;
requirements (such as mandatory cryptographic algorithms to be supported) but more extensive discussion&lt;br /&gt;
of threats and countermeasures to be considered when profiling SAML 2.0.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Privacy&amp;#039;&amp;#039;&amp;#039;: There is discussion of achieving privacy through confidentiality of the transaction and a discussion of&lt;br /&gt;
pseudonymity. Privacy protections implemented for PII at rest seems to be out of scope.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Security&amp;#039;&amp;#039;&amp;#039;: The threat analysis within explains design choices within SAML or informs the developers of SAML profiles.&lt;br /&gt;
The document requires SHA-1 with no mention of more robust hash algorithms (SHA-256 etc did not exist in&lt;br /&gt;
2005), requires Triple DES and suggests but does not mandate AES.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Interoperability&amp;#039;&amp;#039;&amp;#039;: The document specifies TLS cipher suites that are required to be supported.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Terms&amp;#039;&amp;#039;&amp;#039;:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Standards]]&lt;br /&gt;
[[Category:Authentication]]&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>