Despite Saml2 being a well established standard for single sign on, it is horrible. Just about every implementation I've investigated has been broken, including finding flaws in .Net Framework's SignedXml implementation.
Looking at how Saml2 approaches the top 10 challenges of a Single Sign On Protocol makes a strong argument on why OpenID Connect is better on every single point.
Check out more of our featured speakers and talks at
https://ndcconferences.com/
https://ndc-security.com/
Watch video Why We Should Kill Saml2 - Anders Abel - NDC Security 2022 online without registration, duration hours minute second in high quality. This video was added by user NDC Conferences 07 June 2022, don't forget to share it with your friends and acquaintances, it has been viewed on our site 1,864 once and liked it 47 people.