SAML의 복잡성이 증가하면서 OpenID Connect로의 전환이 필요하다.
SAML은 SSO 산업의 근본적인 기술이 되었지만, XML과 서명 검증의 복잡성이 점점 더 커지고 있습니다. XML 서명 래핑(XSW) 공격이 여전히 발생하고 있으며, 이러한 문제를 해결하기 위해 OpenID Connect(OIDC)로 전환할 필요성이 커지고 있습니다. 이로 인해 SAML의 설계가 더 이상 적합하지 않다는 주장이 제기되고 있습니다.
The complexity of SAML increases the need for a transition to OpenID Connect.
SAML has become a foundational technology in the SSO industry, but the complexity of XML and signature validation is growing. The XML Signature Wrapping (XSW) attack is still occurring, highlighting the need for a transition to OpenID Connect (OIDC). This raises concerns that the current design of SAML may no longer be suitable.