No video

SAML vs. OpenID (OIDC): What's the Difference?

  Рет қаралды 41,528

JumpCloud

JumpCloud

Жыл бұрын

In this video, learn the differences between Security Assertion Markup Language (SAML 2.0) and OIDC, which is built on the OAuth 2.0 framework. Read the full post: jumpcloud.com/...
Learn more about SSO with JumpCloud: jumpcloud.com/...
Try JumpCloud for free: jumpcloud.com/...
Resources and social media:
-Blog: jumpcloud.com/...
-Community: community.jump...
-Facebook: / jumpcloud.daas
-Twitter: / jumpcloud
-LinkedIn: / jumpcloud
#jumpcloud #sso #singlesignon #oauth2 #saml
Transcript:
OpenID Connect and SAML are both used for single sign-on or SSO, and the sign-in process is similar. However, there are distinct technical differences to assess before you begin your project. SAML allows an identity provider or IDP to securely federate identity for authentication and authorization into web apps. SAML can be more difficult for service providers or SPs to implement, and some even charge for it. It requires XML schema to transmit user information. That aspect can be very granular for managing access, control, and permissions, but it also adds some complexity. That's where OpenID comes in. It can be simpler for SPs to implement because it's lightweight and high performance. It's only focused on authentication. That makes it a popular choice for managing sign-in flows and assertions for mobile applications.
SAML is a widely used mature SSO protocol. Passwords aren't sent over the wire or stored with SPs. It signs users in with one set of credentials, but also can authorize access to resources between the IDP and the SP. XML documents transmit assertions about the user, who they are, and how that information was issued. Web browsers help to make this happen and SAML is always going to be used for websites. OpenID is based on the OAUTH 2.0 standard and works a bit differently. Users are redirected from the relying party, RP, to the OpenID provider, OP, as opposed to IDPs and SPs. There are direct calls between the RP and OP using REST and JSON message flows that are accessible using APIs.
ID tokens transmit information, or claims, about the user versus it being contained in SAML's XML documents. Claims are OpenID's equivalent to SAML assertions. The difference in how identity information is released between the protocols means that OpenID can be used for both websites and applications. Both SAML and OpenID are authentication protocols, and it's not a binary choice. They can be used in combination with other authentication standards depending on the use case. For example, a subject matter expert within the healthcare industry would use SAML for secure application portal access, but a mobile app would benefit from the efficiencies of OpenID. The choice comes down to your technical requirements, what applications your organization is using, and the resources that are available to implement SSO.
JumpCloud offers both SAML and OpenID configurations for SSO implementation, as well as pre-built and custom connectors. Learn more at the link in the description below.

Пікірлер: 2
@aurisme
@aurisme 6 ай бұрын
Nice explanation !! Well done mate
@Buzca
@Buzca 10 ай бұрын
👍
What Is Bring Your Own Device (BYOD)?
3:28
JumpCloud
Рет қаралды 6 М.
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 577 М.
Smart Sigma Kid #funny #sigma #comedy
00:40
CRAZY GREAPA
Рет қаралды 38 МЛН
Little brothers couldn't stay calm when they noticed a bin lorry #shorts
00:32
Fabiosa Best Lifehacks
Рет қаралды 18 МЛН
Survive 100 Days In Nuclear Bunker, Win $500,000
32:21
MrBeast
Рет қаралды 157 МЛН
What is SAML? A Comprehensive Guide with Examples
9:52
ByteMonk
Рет қаралды 27 М.
LDAP vs SAML: What's the Difference?
3:49
JumpCloud
Рет қаралды 56 М.
FIDO Promises a Life Without Passwords
9:58
IBM Technology
Рет қаралды 401 М.
OAuth 2.0 & OpenID Connect (OIDC): Technical Overview
16:19
VMware End-User Computing
Рет қаралды 156 М.
SSO: SAML vs OAUTH vs OIDC
6:24
Xploit Cyber Security
Рет қаралды 69 М.
A Developer's Guide to SAML
27:47
OktaDev
Рет қаралды 178 М.
Kerberos vs. LDAP: What’s the Difference?
3:46
JumpCloud
Рет қаралды 38 М.
OAuth and OpenID Connect - Know the Difference
10:18
Viraj Shetty
Рет қаралды 3,9 М.
Smart Sigma Kid #funny #sigma #comedy
00:40
CRAZY GREAPA
Рет қаралды 38 МЛН