关于php-saml集成OneLogin的SAML认证配置安全性问询
Hey there! Let's take a close look at your current SP metadata and break down the security implications of your settings:
First, let's clarify what those two disabled flags mean
AuthnRequestsSigned="false": When this is disabled, your Service Provider (SP) doesn't sign the authentication requests it sends to OneLogin. This leaves you open to tampering attacks—an attacker could modify the request (like changing the target IDP URL or entity ID) to redirect users to a malicious login page, or forge authentication requests entirely.WantAssertionsSigned="false": This is a bigger red flag. Disabling this means your SP doesn't require OneLogin's identity assertions (the data that confirms a user's identity) to be signed. Without signature validation, an attacker could craft a fake assertion and send it directly to your SP's ACS endpoint, allowing them to impersonate any user on your platform.
Even though you've included an x509cert in your metadata, those flags being false mean the certificate isn't being used for its intended security purposes—signing outgoing requests or verifying incoming assertions.
Recommended Fixes to Secure Your Configuration
To harden your SAML integration, you'll need to make these changes to your metadata and corresponding php-saml settings:
- Set
AuthnRequestsSigned="true": This ensures every authentication request from your SP is signed with your private key. OneLogin will use your public key (from the x509cert in your metadata) to verify the request hasn't been tampered with. - Set
WantAssertionsSigned="true": This forces OneLogin to sign all assertions with its private key. Your SP will then use OneLogin's public key to validate that the assertion is genuine and unaltered. - Verify your php-saml settings: Make sure your
settings.phpfile correctly references your SP's private key and x509 certificate, along with OneLogin's x509 certificate. These are required for the signing and validation processes to work properly.
While your setup works functionally right now, skipping these security checks exposes your platform to serious identity spoofing and request tampering risks. Enabling these flags is critical for a secure SAML implementation.
内容的提问来源于stack exchange,提问作者Owow

