identity federation - security testing (what to test for/how to test)

From: secmail.lists@gmail.com
Date: Fri Sep 14 2007 - 12:58:01 EDT


('binary' encoding is not supported, stored as-is) All -

I have a project coming up where Federation will be used b/w to COTS SSO products (Sun Access Manager/ Sitemeinder)to all cross-domain sign-on. What I am stumped on is how would one go about testing? The implemented SSO systems have both been tested yet this project extends that with Federation.

Your feedback is welcomed.

Thanks
David

------------------------------------------------------------------------
This list is sponsored by: Cenzic

Need to secure your web apps NOW?
Cenzic finds more, "real" vulnerabilities fast.
Click to try it, buy it or download a solution FREE today!

http://www.cenzic.com/downloads
------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:58:07 EDT