From Surf Wiki (app.surf) — the open knowledge base
SAML-based products and services
List of computer security products
List of computer security products
Security Assertion Markup Language (SAML) is a set of specifications that encompasses the XML-format for security tokens containing assertions to pass information about a user and protocols and profiles to implement authentication and authorization scenarios. This article has a focus on software and services in the category of identity management infrastructure, which enable building Web-SSO solutions using the SAML protocol in an interoperable fashion. Software and services that are only SAML-enabled do not go here.
Products that provide SAML actors
SAML actors are Identity Providers (IdP), Service Providers (SP), Discovery Services, ECP Clients, Metadata Services, or Broker/IdP-proxy. This table shows the capability of products according to Kantara Initiative testing. Claimed capabilities are in column "other". Each mark denotes that at least one interoperability test was passed. Detailed results with product and test procedure versions are available at the Kantara/Liberty site given below.
NOTE: This table represents a snapshot over time roll up of the most recent product test results (multiple testing rounds). Please note that some products features and abilities may have been updated since they were last tested. Please check the website information of the originating product for the latest features and updates.
| Product Name | Project/Vendor | License | Kantara-certified Interoperability | Other Features | nb=1 | stp=1 | IdP}} | nb=1 | stp=1 | IdP Light}} | nb=1 | stp=1 | SP}} | nb=1 | stp=1 | SP Light}} | nb=1 | stp=1 | eGov 1.5}} | nb=1 | stp=1 | Attr Auth Resp}} | nb=1 | stp=1 | POST Bind.}} | Roles | Protocols |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 10Duke Identity Provider | 10Duke | ||||||||||||||||||||||||||
| adAS SSO | PRiSE | ||||||||||||||||||||||||||
| ADFS 1.x | Microsoft | ||||||||||||||||||||||||||
| ADFS 2.0 | Microsoft | ||||||||||||||||||||||||||
| ADFS 2.1 | Microsoft | ||||||||||||||||||||||||||
| ADFS 3.0 | Microsoft | ||||||||||||||||||||||||||
| ADFS 4.0 | Microsoft | ||||||||||||||||||||||||||
| Aerobase | Aerobase | ||||||||||||||||||||||||||
| Afrilas | Able - AXS Guard | ||||||||||||||||||||||||||
| Asimba | Asimba.org | ||||||||||||||||||||||||||
| AssureBridge SAMLConnect | AssureBridge | ||||||||||||||||||||||||||
| Auth0 | Auth0 | ||||||||||||||||||||||||||
| Authentic2 | Entrouvert | ||||||||||||||||||||||||||
| AuthStack | Buckhill | ||||||||||||||||||||||||||
| BIG-IP Access Policy Manager | F5 Networks | ||||||||||||||||||||||||||
| Bitium | Bitium | ||||||||||||||||||||||||||
| CA Single Sign-On | CA | ||||||||||||||||||||||||||
| Central Authentication Server (CAS) | Apereo Foundation | ||||||||||||||||||||||||||
| Centrify DirectControl | Centrify | ||||||||||||||||||||||||||
| Ceptor | Ceptor | ||||||||||||||||||||||||||
| cidaas | cidaas by Widas ID GmbH | ||||||||||||||||||||||||||
| Citrix Open Cloud | Citrix | ||||||||||||||||||||||||||
| Cloud Identity Manager | McAfee | ||||||||||||||||||||||||||
| Cloud Federation Service | Radiant Logic | ||||||||||||||||||||||||||
| Cloudseal | Cloudseal | SaaS | |||||||||||||||||||||||||
| Cognito | Amazon | ||||||||||||||||||||||||||
| Comfact IDP | Comfact | ||||||||||||||||||||||||||
| Signicat | Signicat | ||||||||||||||||||||||||||
| Corto https://sites.google.com/site/cortopages/ | Corto project home | GÉANT | |||||||||||||||||||||||||
| DACS | Safran Identity & Security | ||||||||||||||||||||||||||
| Dot Net Workflow | The Dot Net Factory | ||||||||||||||||||||||||||
| DirX Access | Atos/Siemens | ||||||||||||||||||||||||||
| DualShield | Deepnet Security | ||||||||||||||||||||||||||
| Elastic SSO Team | 9STAR | ||||||||||||||||||||||||||
| Elastic SSO Enterprise | 9STAR | ||||||||||||||||||||||||||
| ESOE | Queensland University of Technology | ||||||||||||||||||||||||||
| Entra ID (formerly known as Azure Active Directory) | Microsoft | ||||||||||||||||||||||||||
| Entrust GetAccess | Entrust | ||||||||||||||||||||||||||
| Entrust IdentityGuard | Entrust | ||||||||||||||||||||||||||
| EIC | Ericsson | ||||||||||||||||||||||||||
| EmpowerID | The Dot Net Factory | ||||||||||||||||||||||||||
| Evidian Web Access Manager | Evidian | ||||||||||||||||||||||||||
| Fluig Identity | TOTVS | ||||||||||||||||||||||||||
| Forum Sentry | Forum Systems | ||||||||||||||||||||||||||
| Fugen Cloud ID Broker | Fugen Solutions | ||||||||||||||||||||||||||
| FusionAuth | FusionAuth | ||||||||||||||||||||||||||
| GlobalSign | GlobalSign SSO | GMO GlobalSign | |||||||||||||||||||||||||
| Gluu Server | Gluu | ||||||||||||||||||||||||||
| Hitachi ID Identity and Access Management Suite | Hitachi ID Systems, Inc. | ||||||||||||||||||||||||||
| Horizon App Manager | VMware | ||||||||||||||||||||||||||
| HP IceWall SSO | HP | ||||||||||||||||||||||||||
| ILANTUS Sign On Express | Ilantus | ||||||||||||||||||||||||||
| Intel Cloud SSO | Intel | ||||||||||||||||||||||||||
| Ilex Sign&go | ILEX | ||||||||||||||||||||||||||
| iSAML | Avoco | ||||||||||||||||||||||||||
| iWelcome | iWelcome | ||||||||||||||||||||||||||
| JOSSO (Community Ed.) | josso.org | ||||||||||||||||||||||||||
| JOSSO (Enterprise Ed.) | Atricore | ||||||||||||||||||||||||||
| Juniper SSL VPN | Juniper Networks | ||||||||||||||||||||||||||
| Keycloak | JBoss | ||||||||||||||||||||||||||
| Layer 7 | SecureSpan Gateway | ||||||||||||||||||||||||||
| Larpe | Entrouvert | ||||||||||||||||||||||||||
| LemonLDAP::NG | LemonLDAP::NG | ||||||||||||||||||||||||||
| LoginRadius | LoginRadius | ||||||||||||||||||||||||||
| MicroFocus (NetIQ) Access Manager | NetIQ (formerly Novell) | ||||||||||||||||||||||||||
| miniOrange | miniOrange | ||||||||||||||||||||||||||
| NetWeaver Appserver | SAP | ||||||||||||||||||||||||||
| OneGate | MobilityGuard | ||||||||||||||||||||||||||
| OpenAM | title=ForgeRock has shuttered the open-source community, and no longer allows new development on their platform under a permissive license | website=timeforafork | date=June 1, 2017 | url=http://www.timeforafork.com/ | ref= | accessdate=June 1, 2017}} | |||||||||||||||||||||
| Okta | Okta | ||||||||||||||||||||||||||
| OneLogin | OneLogin | ||||||||||||||||||||||||||
| OpenAthens LA | eduserv | ||||||||||||||||||||||||||
| OpenAthens SP | eduserv | ||||||||||||||||||||||||||
| Open Select | OpenASelect.org | ||||||||||||||||||||||||||
| Optimal IdM VIS Federation Services | Optimal IdM | ||||||||||||||||||||||||||
| Oracle Identity Federation 11g | Oracle | ||||||||||||||||||||||||||
| Pega 7 Platform | Pegasystems Inc. | ||||||||||||||||||||||||||
| PhoneFactor | PhoneFactor, Inc | ||||||||||||||||||||||||||
| PicketLink | JBoss Community | ||||||||||||||||||||||||||
| PingFederate | Ping Identity | ||||||||||||||||||||||||||
| Plurilock AI | Plurilock | ||||||||||||||||||||||||||
| PortalGuard | PistolStar, Inc. | ||||||||||||||||||||||||||
| RSA Federated Identity | RSA | ||||||||||||||||||||||||||
| SAASPASS | SAASPASS | ||||||||||||||||||||||||||
| Safewhere*Identify | Safewhere | ||||||||||||||||||||||||||
| SailPoint IdentityNow | SailPoint | ||||||||||||||||||||||||||
| Samanage | Samanage | ||||||||||||||||||||||||||
| SATOSA | SATOSA | ||||||||||||||||||||||||||
| SecureAuth | SecureAuth Corp. | ||||||||||||||||||||||||||
| SecureSSO | SurePassID | ||||||||||||||||||||||||||
| Shibboleth | Internet2 | ||||||||||||||||||||||||||
| SimpleSAMLphp | UNINETT AS | ||||||||||||||||||||||||||
| Smartsignin | PerfectCloud | ||||||||||||||||||||||||||
| SMS PASSCODE Multi-factor Authentication | SMS PASSCODE | ||||||||||||||||||||||||||
| SSO EasyConnect | SSO Easy | ||||||||||||||||||||||||||
| SSOgen | SSOGEN Corporation | ||||||||||||||||||||||||||
| Symlabs Federated Identity Suite | Symlabs | ||||||||||||||||||||||||||
| Symplified | Symplified | ||||||||||||||||||||||||||
| Tivoli Federated Identity Manager | IBM | ||||||||||||||||||||||||||
| TrustBind | NTT Software Corp | ||||||||||||||||||||||||||
| TrustBuilder | SecurIT | ||||||||||||||||||||||||||
| Trustelem | Trustelem | ||||||||||||||||||||||||||
| USP Secure Entry Server | United Security Providers | ||||||||||||||||||||||||||
| Weblogic | Oracle | ||||||||||||||||||||||||||
| WSO2 | wso2 | ||||||||||||||||||||||||||
| ZITADEL | ZITADEL | ||||||||||||||||||||||||||
| ZXID | zxid |
Libraries and toolkits to develop SAML actors and SAML-enabled services
Libraries and toolkits are used by developers to integrate applications and services into SAML federations or to build their own SAML-actors like IdPs.
| Libraries and Toolkits | Organization | Licence | Purpose and Language bindings |
|---|---|---|---|
| Australian Access Federation | Australian Access Federation | Metadata Registry based on former work by SWITCH | |
| ComponentSpace | ComponentSpace | SAML libraries for ASP.NET and ASP.NET Core applications | |
| Corto | WAYF | SAML2 proxy, virtual IdP, user consent | |
| DjangoSAML2 | GitHub | SAML2 application for Django, using PySAML2 underneath | |
| EmpowerID IdP & SP Kit | Dot Net Factory | IdP and SP Kit, .NET, REST, and SOAP-based integration kit to SAML-enable applications | |
| FEMMA | SourceForge | Workaround for the ADFS limitation of a single EntityID per XML infoset | |
| Firefox ECP Plugin | Openliberty | Firefox extension for compliance with SAML ECP | |
| FLOG F-Ticks Vizualization | SUNET | Parse and chart F-Ticks for webSSO and Eduroam | |
| Jagger | HEAnet | Metadata and Federation data manager; Shibboleth IDP GUI | |
| JAKOB | WAYF | Backchannel attribute collector | |
| JANUS | WAYF | Metadata Registry for hub-and-spoke federations based on SimpleSAMLphp; includes self-service | |
| Jitbit ASP.NET SAML lib | GitHub | SAML 2.0 "consumer" component for ASP.NET | |
| Lasso | Entrouvert | SAML-Library: C/C++, Python, Java, Perl, PHP | |
| LightSAML core | SAML-Library: PHP | ||
| OIOSAML 2.0 Toolkit | Danish IT and Telekom Agency | SP Framework: Java, .NET, PHP (Documentation see OIOSAML.java) | |
| OmniAuth-Shibboleth | OneLogin | SAML-Library: ASP/.NET, Java, PHP, Python, Ruby | |
| OneLogin | OneLogin | SAML-Library: ASP/.NET, Java, PHP, Python, Ruby | |
| OpenConext | SURFnet | Service Provider Proxy and Hub-and-Spoke federation middleware, includes SAML proxy and central group management for creating collaboration platforms | |
| OpenSAML | Internet2 | SAML-Library: C++, Java | |
| MET | TERENA | gathers and shows information about federations (mostly about SPs and IdPs) | |
| Mujina | SURFnet | SAML test actors that can be dynamically configured using a REST interface | |
| PAC4J-SAML | SAML Service Provider Library (and other authentication mechanisms) | ||
| PEER | GÉANT | SAML Metadata Registry | |
| PHPH | WAYF.dk | SAML Metadata Processor | |
| Ping Identity | Ping Identity | Java, .NET, PHP and language neutral integration kits to SAML-enable applications | |
| PySAML2 | GitHub | SAML-Library: Python | |
| Python-SAML | OneLogin | SAML-Library: Python | |
| Pysfemma | GitHub | automate membership configuration of an ADFS STS in a SAML2 based Identity Federation | |
| PyFF | SUNET | SAML Metadata Processor | |
| Raptor | Jisc | toolkit to enable Shibboleth IdP statistics analysis | |
| SAML Metadata Aggregator | NORDUnet | Aggregates single metadata files and provides MDX webservice | |
| SAML Tracer (Firefox addon) | UNINETT AS | Firefox Plug-In to trace SAML messages | |
| SecureBlackbox | /n software | The component that implements SAML in client apps, which need to use service providers, or can be used to create your own service and identity providers | |
| SpringSecurity SAML | SpringSource | SAML-enable applications based on Spring framework | |
| Switch GMT | SWITCH-AAI | Group Management Tool for Shibboleth | |
| Webisoget | Command-line Tool to fetch a SSO-protected page including Shibboleth-Login | ||
| ZXID | zxid | C, other lang using swig.org |
References
References
- "Kantara Initiative 2011 Q1 SAML 2.0 Full-Matrix Interoperability Testing".
- (12 November 2021). "Liberty Alliance SAML interoperability tests".
- (11 February 2022). "10Duke Identity Provider".
- "adAS SSO".
- "Open Source Identity & Access Management".
- "Aerobase". Aerobase Org.
- "Afrilas".
- "Asimba".
- "AssureBridge".
- "Auth0".
- "Authentic2".
- "Authstack - Identity Access Management (IAM) and Single Sign-On Software".
- "Bitium Single Sign-on".
- "CA Federation Manager".
- "CAS SAML2 Authentication".
- "Secure IT Infrastructure for Online Business Applications {{!}} Ceptor".
- "cidaas – European Cloud Identity and Access Management".
- "Citrix Open Cloud Access".
- "RadiantOne Cloud Federation Service".
- "Cloudseal SSO for Java".
- "Amazon Cognito: SAML identity providers (identity pools)".
- "Comfact IDP".
- "Signicat".
- "Morpho DACS".
- "Dot Net Workflow cloud and corporate SSO and Federation".
- "DirX Access".
- "DualShield unified authentication platform".
- (16 October 2018). "9STAR's Elastic SSO Team".
- (16 October 2018). "9STAR's Elastic SSO Enterprise".
- "Entrust GetAccess".
- "Entrust IdentityGuard".
- "EIC".
- "EmpowerID".
- "API Security Gateway".
- "FusionAuth Community Edition".
- (30 March 2020). "GlobalSign SSO". Globalsign.
- "Open Source Access Management".
- "IAM Solutions".
- "Horizon App Manager".
- "HP IceWall SSO".
- (10 September 2019). "ILANTUS Xpress Sign-On".
- "Intel Cloud SSO".
- "Ilex".
- "Avoco Identity".
- "iWelcome".
- "JOSSO (Community Edition)".
- "JOSSO (Enterprise Edition)".
- "Juniper SSL VPN".
- "Keycloak". JBoss Community.
- "Layer 7".
- "Larpe".
- "LemonLDAP::NG".
- "NetIQ Access Manager".
- "NetWeaver Appserver".
- "Mobilityguard OneGate".
- (June 1, 2017). "ForgeRock has shuttered the open-source community, and no longer allows new development on their platform under a permissive license".
- "Cloud service platform".
- "OneLogin Single Sign On".
- "OpenAthens LA".
- "OpenAthens SP".
- "OpenASelect".
- "Optimal IdM VIS Federation Services".
- "Oracle Identity Federation 11g".
- (15 September 2020). "Pega7".
- "PhoneFactor".
- "PicketLink".
- "PingFederate".
- "Plurilock AI Cloud".
- "DEFEND Continuous Authentication".
- "PortalGuard".
- "RSA Federated Identity Manager".
- "Safewhere*Identify".
- "SailPoint IdentityNow".
- "Samanage".
- (25 October 2021). "Github/SATOSA".
- "SecureAuth".
- "SurePassID".
- "SimpleSAMLphp".
- "Smartsignin Single Sign-on".
- "SMS PASSCODE".
- "SSO EasyConnect".
- "Symlabs Federated Identity Suite".
- "Symplified".
- (9 November 2020). "Tivoli Federated Identity Manager".
- "TrustBind/Federation Manager".
- "TrustBuilder".
- "Trustelem Cloud SSO {{!}} Active Directory and multi-factor authentication".
- "USP Secure Entry Server".
- "WSO2".
- "ZITADEL".
- "ZXID".
- "Federation Registry".
- "ComponentSpace".
- "cortoweb".
- "knaperek/djangosaml2".
- "EmpowerID Dot Net Workflow Idp & SP Kit".
- (May 2015). "Federation Metadata Manager for ADFS".
- "Firefox ECP Plugin".
- (8 May 2020). "FLOG".
- (20 October 2021). "JAGGER (ResourceRegistry3".
- "JAKOB Attribute Collector".
- (21 March 2020). "JANUS".
- (13 April 2022). "Jitbit SAML toolkil".
- "Lasso".
- "LightSAML core".
- "OIOSAML 2.0 Toolkit".
- "OIOSAM.net Service Provider Framework".
- (16 December 2020). "Shibboleth Binding for OmniAuth 1.x".
- "SAML Toolkits from OneLogin".
- "OpenConext".
- "OpenSAML".
- (14 January 2021). "Metadata Explorer Tool".
- (13 April 2022). "Mujina Mock IdP and SP".
- "PAC4J Security Engine".
- (26 June 2018). "PEER".
- (7 June 2015). "PHPH".
- "PingFederate Integration Kits".
- (13 April 2022). "PySAML2".
- (28 January 2019). "Pysfemma".
- "PyFF".
- "Raptor".
- "SAML Metadata Aggregator".
- "SAML Tracer".
- "SAMLBlackbox (SAML component and class library) - SecureBlackbox".
- "SpringSecurity SAML Site".
- "SWITCH Group Management Tool".
- "Webisoget - eduGAIN Wiki".
- "ZXID".
- (23 October 2018). "9STAR Shibboleth/SAML SSO Services". 9STAR.
- (16 October 2018). "9STAR Shibboleth/SAML SSO Support".
- "Arcot A-OK".
- "eduTEAMs".
- "Federation Lab".
- "Feide OpenIdP".
- "Gazelle IHE interop test framework".
- "Gluu On-Prem Managed Service".
- "Identity Hub".
- "OneLogin SSO".
- "RE:EP".
- "Phonefactor".
- "PingOne".
- "SAML .NET Dev Zone".
- "samlidp.io - SAML Identity Provider as a Service".
- "SecureAuth Corp.".
- "SSO Circle IDP".
- "Testshib.org".
- "United ID".
- "Verizon Web Access Management as a Service".
- "ZXIDP.org".
This article was imported from Wikipedia and is available under the Creative Commons Attribution-ShareAlike 4.0 License. Content has been adapted to SurfDoc format. Original contributors can be found on the article history page.
Ask Mako anything about SAML-based products and services — get instant answers, deeper analysis, and related topics.
Research with MakoFree with your Surf account
Create a free account to save articles, ask Mako questions, and organize your research.
Sign up freeThis content may have been generated or modified by AI. CloudSurf Software LLC is not responsible for the accuracy, completeness, or reliability of AI-generated content. Always verify important information from primary sources.
Report