SAML-based products and services
{{short description|List of computer security products using Security Assertion Markup Language}}
Security Assertion Markup Language (SAML) is a set of specifications that encompasses the XML-format for security tokens containing assertions to pass information about a user and protocols and profiles to implement authentication and authorization scenarios. This article has a focus on software and services in the category of identity management infrastructure, which enable building Web-SSO solutions using the SAML protocol in an interoperable fashion. Software and services that are only SAML-enabled do not go here.
Products that provide SAML actors
SAML actors are Identity Providers (IdP), Service Providers (SP), Discovery Services, ECP Clients, Metadata Services, or Broker/IdP-proxy. This table shows the capability of products according to Kantara Initiative testing.{{Cite web| url=http://kantarainitiative.org/confluence/display/certification/2011+Q1+Kantara+Initiative+SAML+2.0+Full-Matrix+Interoperability+Testing | title= Kantara Initiative 2011 Q1 SAML 2.0 Full-Matrix Interoperability Testing}}{{Cite web| url =http://projectliberty.org/liberty/liberty_interoperable/implementations/?f=liberty/liberty_interoperable/implementations | title= Liberty Alliance SAML interoperability tests| date= 12 November 2021}} Claimed capabilities are in column "other". Each mark denotes that at least one interoperability test was passed. Detailed results with product and test procedure versions are available at the Kantara/Liberty site given below.
NOTE: This table represents a snapshot over time roll up of the most recent product test results (multiple testing rounds). Please note that some products features and abilities may have been updated since they were last tested. Please check the website information of the originating product for the latest features and updates.
class="wikitable sortable" border="1"
! rowspan="3" | Product Name ! rowspan="3" | Project/Vendor ! rowspan="3" | License ! colspan="7" | Kantara-certified Interoperability ! colspan="8" | Other Features | |||||||||||||||||
rowspan="2" {{verth|nb=1|stp=1| IdP}}
! rowspan="2" {{verth|nb=1|stp=1| IdP Light}} ! rowspan="2" {{verth|nb=1|stp=1| SP}} ! rowspan="2" {{verth|nb=1|stp=1| SP Light}} ! rowspan="2" {{verth|nb=1|stp=1| eGov 1.5}} ! rowspan="2" {{verth|nb=1|stp=1| Attr Auth Resp}} ! rowspan="2" {{verth|nb=1|stp=1| POST Bind.}} ! colspan="7" | Roles ! rowspan="2" | Protocols | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
{{verth|nb=1|stp=1|Broker}}
! {{verth|nb=1|stp=1|Discovery}} ! {{verth|nb=1|stp=1|ECP}} ! {{verth|nb=1|stp=1|IdP}} ! {{verth|nb=1|stp=1|IdP Proxy}} ! {{verth|nb=1|stp=1|Reverse Proxy}} ! {{verth|nb=1|stp=1|SP}} | |||||||||||||||||
10Duke Identity Provider{{Cite web| url= https://www.10duke.com/products/identity-provider/ | title=10Duke Identity Provider| date=11 February 2022}} | 10Duke | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, OAuth 2, OpenID, LDAP, Federation | ||||||||||||||
adAS SSO{{Cite web| url= http://www.adas-sso.com/en | title=adAS SSO}}
| PRiSE | {{Open source|OSS}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 2.0, SAML 1.0, Google, Microsoft365, Facebook, Twitter, Kerberos, LDAP, Federation, OAuth2, OpenID Connect, CAS v1, CAS v2, PAPI, OpenID | |||||||||||||||||
ADFS 1.x | Microsoft | {{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | WS-Federation, WS-Trust, SAML 1.0 | ||||||||||
ADFS 2.0 | Microsoft | {{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | WS-Federation, WS-Trust, SAML 1.1/2.0 | ||||||||||
ADFS 2.1 | Microsoft | {{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | WS-Federation, WS-Trust, SAML 2.0 | ||||||||||
ADFS 3.0 | Microsoft | {{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | WS-Federation, WS-Trust, SAML 2.0, OAuth2 | ||||||||||
ADFS 4.0 | Microsoft | {{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | |WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect | ||||||||||
Aerobase{{cite web | title=Open Source Identity & Access Management | website=Aerobase | url=https://aerobase.io/ | access-date=2024-08-17}}
|Aerobase | {{Open source|OSS}} | {{ya}} | {{ya}} | {{ya}} | Integrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications{{cite web|url=https://www.aerobase.io|title=Aerobase|publisher=Aerobase Org}} | ||||||||||||
Afrilas{{Cite web | url= http://www.afrilas.com | title=Afrilas}} | Able - AXS Guard | {{Proprietary|Commercial}} | {{ya}} | {{ya}} | |SAML 2.0 Strong Authentication without usernames | ||||||||||||
Asimba{{Cite web | url= http://www.asimba.org | title=Asimba}}
|Asimba.org |{{Open source|OSS}} | | | | | | | | | | | {{ya}} | | | |(Fork of OpenASelect) | |||||||||||||||||
AssureBridge SAMLConnect{{Cite web | url=http://www.assurebridge.com/ | title=AssureBridge}} | AssureBridge | {{Proprietary|Commercial}}
| | {{ya}} | | {{ya}} | | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, OpenID, WS-Federation, Kerberos, Radius, X509, LDAP | |||||||||||||||
Auth0{{Cite web|url=https://auth0.com/|title=Auth0|last=|first=|date=|website=Auth0|language=en|access-date=2019-12-12}}
|Auth0 |{{Proprietary|Commercial}} | {{ya}} | | {{ya}} | | | | | | | | {{ya}} | | | {{ya}} |OAuth2, OpenID, SAML 1.1, SAML 2.0, WS-Federation, LDAP | |||||||||||||||||
Authentic2{{Cite web| url= https://dev.entrouvert.org/ | title=Authentic2}} | Entrouvert | {{Open source|OSS}} | |
| | | {{ya}} | | | {{ya}} |OpenID 1&2, CAS 1&2, OAuth2, LDAP 2&3, PAM, RADIUS, OATH, Kerberos, X509 | ||||||||||||||
AuthStack{{Cite web|url=https://www.buckhill.co.uk/products/authstack-single-sign-on|title=Authstack - Identity Access Management (IAM) and Single Sign-On Software|website=www.buckhill.co.uk|language=en|access-date=2017-05-15}}
|Buckhill |{{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 1.0, SAML 1.1, SAML 2.0, LDAP, Kerberos, X509, RADIUS, OAuth2, SOAP/REST API | |||||||||||||||||
BIG-IP Access Policy Manager | F5 Networks | {{Proprietary|Commercial}} | |
| {{ya}} | | | {{ya}} | | | {{ya}} |SAML 2.0 | ||||||||||||||
Bitium{{Cite web | url=http://www.bitium.com/site/product/single-sign-on/ | title=Bitium Single Sign-on}} | Bitium | {{Proprietary|Commercial}} | |
| | {{ya}} | | | {{ya}} |SAML, SAML 2.0 | ||||||||||||||
CA Single Sign-On{{Cite web | url=http://www.ca.com/us/products/detail/CA-Federation-Manager.aspx | title=CA Federation Manager}} | CA | {{Proprietary|Commercial}} | | {{ya}}
| | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 1.0/1/1/2.0, OAuth2, OpenID, WS-Federation | ||||||||||||||
Central Authentication Server (CAS){{Cite web | url=https://apereo.github.io/cas/5.1.x/installation/Configuring-SAML2-Authentication.html | title=CAS SAML2 Authentication}} | Apereo Foundation | {{Open source}}
| {{ya}} | |
| | | | {{ya}} | | | |SAML 2.0, OAuth2, OpenID, WS-Federation | ||||||||||||||
Centrify DirectControl | Centrify | {{Proprietary|Commercial}} | | {{ya}}
| | | | | | | SAML, OpenID, OAuth, WS-*, LDAP, Kerberos | ||||||||||||||
Ceptor{{Cite web|url=https://ceptor.io|title=Secure IT Infrastructure for Online Business Applications {{!}} Ceptor|website=Ceptor|language=en-US|access-date=2018-02-26}}
|Ceptor | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} |SAML 1.1/2.0, OAuth 2.0, WS-Federation, OpenID Connect, Kerberos | ||||||||||||||||
cidaas{{Cite web|title=cidaas – European Cloud Identity and Access Management|url=https://www.cidaas.com/|access-date=2020-11-21|website=cidaas|language=en-US}}
|cidaas by Widas ID GmbH |{{Proprietary|Commercial}} | | | | | | | | | | | {{ya}} | | | {{ya}} |SAML 2.0, OAuth2, OpenID Connect | |||||||||||||||||
Citrix Open Cloud{{Cite web | url= http://www.citrix.com/English/ps2/products/subfeature.asp?contentID=2300426 | title=Citrix Open Cloud Access}} | Citrix | {{Proprietary|Commercial}} | | {{ya}}
| | | | | | |SSO Middleware, native service connectors | ||||||||||||||
Cloud Identity Manager | McAfee | {{Proprietary|Commercial}} | | {{ya}}
| | | | | | | SAML 2, OpenID, OAuth, XACML, LDAP v3, JM | ||||||||||||||
Cloud Federation Service{{Cite web | url=http://www.radiantlogic.com/products/radiantone-cfs/ | title=RadiantOne Cloud Federation Service}} | Radiant Logic | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 2.0, WS-Federation, OAuth 2.0, OpenID | ||||||||||||||
Cloudseal{{Cite web | url=http://www.cloudseal.com/ | title=Cloudseal SSO for Java}} | Cloudseal | SaaS | |
| | | {{ya}} | | | {{ya}} | | ||||||||||||||
Cognito{{Cite web | url= https://docs.aws.amazon.com/cognito/latest/developerguide/saml-identity-provider.html |title= Amazon Cognito: SAML identity providers (identity pools)}} | Amazon | {{Proprietary|Commercial}} | | | |
| {{ya}} | | | | SAML 2.0 | |||||||||||||
Comfact IDP{{Cite web | url= https://www.comfact.com/Product/IdP |title= Comfact IDP}} | Comfact | {{Proprietary|Commercial}} | | | |
| {{ya}} | | | | | |||||||||||||
Signicat{{Cite web | url=http://www.signicat.com/ | title=Signicat}} | Signicat | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} | | ||||||||||||||
Corto https://sites.google.com/site/cortopages/ | Corto project home | GÉANT | {{Open source|OSS}} | | {{ya}}
| | | | | | | | ||||||||||||||
DACS{{Cite web| url=https://www.morpho.com/sites/morpho/files/strong_authentication_macs_morpho_access_control_server_en.pdf | title=Morpho DACS}} | Safran Identity & Security | {{Proprietary|Commercial}} | |
| | | {{ya}} | {{ya}} | | |SSO, OpenID Connect, OATH & OCRA, SMS, X509v3 Certificate, eID card, FIDO UAF, LDAP/AD, multi-factor | ||||||||||||||
Dot Net Workflow{{Cite web | url=http://www.thedotnetfactory.com/products/federationservices | title=Dot Net Workflow cloud and corporate SSO and Federation}} | The Dot Net Factory | {{Proprietary|Commercial}}
| {{ya}} | | {{ya}} | | | | | | | | {{ya}} | | | {{ya}} | WS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN) | |||||||||||||||
DirX Access{{Cite web | url=http://atos.net/en-us/solutions/identity-security-and-risk-management/identity-and-access-management-with-dirx/default.htm | title=DirX Access | access-date=2011-07-03 | archive-date=2011-07-18 | archive-url=https://web.archive.org/web/20110718124349/http://atos.net/en-us/solutions/identity-security-and-risk-management/identity-and-access-management-with-dirx/default.htm | url-status=dead }} | Atos/Siemens | {{Proprietary|Commercial}}
| | {{ya}} | | {{ya}} | | {{ya}} | | | | | | | | | | |||||||||||||||
DualShield{{Cite web | url=http://www.deepnetsecurity.com/solutions/cloud/saml/ | title=DualShield unified authentication platform}} | Deepnet Security | {{Proprietary|Commercial}}
| | {{ya}} | | {{ya}} | | {{ya}} | {{ya}} | | | | {{ya}} | | | |SAML 2.0 | |||||||||||||||
Elastic SSO Team{{Cite web | url=http://www.9starinc.com/solutions/elasticsso-team | title=9STAR's Elastic SSO Team| date=16 October 2018}} | 9STAR | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | | | | {{ya}} | {{ya}} | | | | {{ya}} | | | |SAML 2.0 SAML 1.1 | |||||||||||||||
Elastic SSO Enterprise{{Cite web | url=http://www.9starinc.com/solutions/elasticsso-enterprise | title=9STAR's Elastic SSO Enterprise| date=16 October 2018}} | 9STAR | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | | | | {{ya}} | {{ya}} | | | | {{ya}} | | | |SAML 2.0 SAML 1.1 | |||||||||||||||
ESOE | |Queensland University of Technology | {{Open source|OSS}} | |
| | | {{ya}} | | | {{ya}} | | ||||||||||||||
Entra ID (formerly known as Azure Active Directory)
|Microsoft |{{Proprietary|Commercial}} | {{ya}} | | | | | | | | | | {{ya}} | | | {{ya}} |SAML 2.0, WS-Federation, Kerberos Constrained Delegation, OAuth 2.0, OpenID Connect | |||||||||||||||||
Entrust GetAccess{{Cite web | url=https://www.entrust.com/products/entrust-getaccess/ | title=Entrust GetAccess}} | Entrust | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 1.0, SAML 1.1, SAML 2.0 | |||||||||||||||
Entrust IdentityGuard{{Cite web | url=https://www.entrust.com/products/entrust-identityguard/ | title=Entrust IdentityGuard}} | Entrust | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | {{ya}} | | | | {{ya}} | | | |SAML 2.0, OpenID | |||||||||||||||
EIC{{Cite web | url=http://www.ericsson.com/products/hp/Ericsson_Identity_Management_bs.shtml | title=EIC}} | Ericsson | {{Proprietary|Commercial}}
| {{ya}} | | | | | | | | | | | | | | |||||||||||||||
EmpowerID{{Cite web | url= http://www.thedotnetfactory.com/ | title=EmpowerID}} | The Dot Net Factory | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} | WS*-, WS-Federation, WS-Trust, OpenID, OAuth 2.0, Facebook, LinkedIn, Twitter, Yahoo, Windows Live (MSN) | |||||||||||||||
Evidian Web Access Manager | Evidian | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, OpenID Connect, CAS 1&2, OAuth2, LDAP v3, RADIUS, OATH, Kerberos, X509, Microsoft365, Google, Multi-factor, SSO, extended integration functionalities, Federation | |||||||||||||||
Fluig Identity | TOTVS | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 2.0 | ||||||||||||||
Forum Sentry{{Cite web | url=https://www.forumsys.com/ | title=API Security Gateway}} | Forum Systems | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |WS-Federation, WS-Trust, SAML 2.0, SAML 1.1, OAuth 1.0.a. OAuth 2, OpenID Connect | ||||||||||||||
Fugen Cloud ID Broker | Fugen Solutions | {{Proprietary|Commercial}} | | {{ya}}
| | | | | | |SAML 1.1, SAML 2.0, WS-Federation, WS-Trust, OpenID, and OAuth | ||||||||||||||
FusionAuth{{Cite web | url= https://fusionauth.io |title=FusionAuth Community Edition}} | FusionAuth | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 2.0, OIDC, OAuth, LDAP | ||||||||||||||
GlobalSign{{Cite news | url= https://globalsign.com/en/products/| title=GlobalSign SSO| newspaper=Globalsign| date=30 March 2020}} | GlobalSign SSO | GMO GlobalSign | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | {{ya}} | | {{ya}} | {{ya}} | | | | |SAML 2.0, ETSI MSS 102 204, TUPAS, WS-Federation, OpenID | |||||||||||||||
Gluu Server{{Cite web | url= http://www.gluu.org |title=Open Source Access Management}} | Gluu | {{Open source|OSS}}
| {{ya}} | {{ya}} | | | | | | | | | {{ya}} | | | |OpenID Connect, UMA, RADIUS, LDAP, FIDO, OAuth | |||||||||||||||
Hitachi ID Identity and Access Management Suite{{Cite web | url= http://www.hitachi-id.com |title=IAM Solutions}} | Hitachi ID Systems, Inc. | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 2.0 | ||||||||||||||
Horizon App Manager{{Cite web | url=http://www.horizonmanager.com/ | title=Horizon App Manager}} | VMware | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | | {{ya}} | | | | | {{dunno}} | | | | | |||||||||||||||
HP IceWall SSO{{Cite web | url=http://h50146.www5.hp.com/products/software/security/icewall/eng/sso/| title=HP IceWall SSO}} | HP | {{Proprietary|Commercial}}
| | | | | | | | | | | | | | {{ya}} | SAML 2 | |||||||||||||||
ILANTUS Sign On Express{{Cite web | url=http://www.ilantus.com/xpress-sign-on/ | title=ILANTUS Xpress Sign-On| date=10 September 2019}} | Ilantus | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} | SAML 2 | |||||||||||||||
Intel Cloud SSO{{Cite web | url=http://www.intelcloudsso.com | title=Intel Cloud SSO}} | Intel | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} | SAML 2, OpenID, OAuth | |||||||||||||||
Ilex Sign&go{{Cite web| url= http://www.ilex.fr/ | title=Ilex}} | ILEX | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |WS-Federation, WS-Trust, SAML 2.0, SAML 1.0, Shibboleth, CAS, Google, Microsoft365, Facebook, Kerberos, LDAP | |||||||||||||||
iSAML{{Cite web | url=http://www.avocoidentity.com/avoco-platform/isaml/ | title=Avoco Identity}} | Avoco | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | | SAML 2, WS-Trust, OpenID | |||||||||||||||
iWelcome{{Cite web | url=http://www.iwelcome.com | title=iWelcome}} | iWelcome | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | | SAML 2, SAML 1.0, WS-Trust, Kerberos, OAuth2, Facebook, google, includes provisioning from-to on-Prem, AD, Multi-factor, extended integration functionalities | |||||||||||||||
JOSSO (Community Ed.){{Cite web | url=http://www.josso.org | title=JOSSO (Community Edition)}} | josso.org | {{Open source|OSS}}
| | | | | | | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML2, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1 | |||||||||||||||
JOSSO (Enterprise Ed.){{Cite web | url= http://www.atricore.com| title=JOSSO (Enterprise Edition)}} | Atricore | {{Proprietary|Commercial}}
| | | | | | | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML2, WS-Fed, OpenID Connect, OAuth2, WS-Trust, SPMLV2, Kerberos, JOSSO1 | |||||||||||||||
Juniper SSL VPN{{Cite web | url= http://www.juniper.net/techpubs/software/ive/releasenotes/j-sa-sslvpn-7.1R1-whatsnew.pdf | title=Juniper SSL VPN}} | Juniper Networks | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} | | |||||||||||||||
Keycloak
|JBoss |{{Open source|OSS}} | | | | | | | | | | | {{ya}} | | | |Integrated SSO and IDM for browser apps and RESTful web services. Built on top of the OAuth 2.0, OpenID Connect, JSON Web Token (JWT) and SAML 2.0 specifications{{cite web|url=http://www.keycloak.org|title=Keycloak|publisher=JBoss Community}} | |||||||||||||||||
Layer 7{{Cite web | url= http://www.layer7tech.com// |title=Layer 7}} | SecureSpan Gateway | {{Proprietary|Commercial}}
| |{{ya}} | |{{ya}} | | | | | | | | | | |PDP/PEP, Auth2, SAML 1.1, SAML2, ABAC, OpenID Connect, XML Firewall | |||||||||||||||
Larpe{{Cite web | url= http://larpe.labs.libre-entreprise.org/ |title=Larpe}} | Entrouvert | {{Open source|OSS}}
| | {{ya}} | | {{ya}} | | | | | | | | | {{ya}} | |SAML, OpenID, CAS, OAuth | |||||||||||||||
LemonLDAP::NG{{Cite web | url= http://lemonldap-ng.org |title=LemonLDAP::NG}} | LemonLDAP::NG | {{Open source|OSS}}
| | | | | | | | | | | {{ya}} | | | {{ya}} |SSO, WS-Federation, CAS, OpenID-Connect, SAML-2, Twitter, Protocol proxy | |||||||||||||||
LoginRadius
|LoginRadius |{{Proprietary|Commercial}} | | | | | | | | | | | {{ya}} | | | {{ya}} |Web SSO, Federation SSO, SAML, OAuth, OIDC, WS-Federation, JWT | |||||||||||||||||
MicroFocus (NetIQ) Access Manager{{Cite web | url= http://www.netiq.com/products/access-manager/ | title=NetIQ Access Manager}} | NetIQ (formerly Novell) | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | {{ya}} | | {{ya}} |WS-Security, WS-Federation, WS-Trust, SAML 1.1 / 2.0, Liberty, Single Sign-on, RBAC, CardSpace, OAuth 2.0, OpenID, STS. Includes out of the box integration with cloud and social media providers (Office 365, Windows Live (MSN), Google, Facebook, Salesforce, Amazon web services and 200+ preconfigured connections to SaaS providers etc.) Integration for Advanced Authentication Framework | |||||||||||||||
miniOrange | miniOrange | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 2.0, OAuth2, OpenID Connect, WS-Fed | |||||||||||||||
NetWeaver Appserver{{Cite web | url= http://www.sdn.sap.com/irj/sdn/nw-identitymanagement | title=NetWeaver Appserver}} | SAP | {{Proprietary|Commercial}} | |
| | |{{dunno}} | | | |CAS, OpenId, Twitter | ||||||||||||||
OneGate{{Cite web|title = Mobilityguard OneGate|url = http://mobilityguard.com/|website = mobilityguard.com|access-date = 2016-02-20}}
|MobilityGuard |{{Proprietary|Commercial}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0 | |||||||||||||||||
OpenAM | Open Identity Community [https://github.com/OpenIdentityPlatform/OpenAM/], ForgeRock (ex. Sun) until 2016{{cite web | title=ForgeRock has shuttered the open-source community, and no longer allows new development on their platform under a permissive license | website=timeforafork | date=June 1, 2017 | url=http://www.timeforafork.com/ | ref={{sfnref | ForgeRock | 2017}} | accessdate=June 1, 2017}} | {{Open source|CDDL}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | {{ya}} | | {{ya}} | | |OpenID Connect, OAuth2, SAML 2.0, SAML 1.1, WS-Federation, WS-Trust, XACML, Liberty, Kerberos, Facebook, Google, Windows Live (MSN) | |||||||||||||||
Okta{{Cite web | url=http://www.okta.com/ | title=Cloud service platform}} | Okta | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect | ||||||||||||||
OneLogin{{Cite web | url=http://www.onelogin.com/product/ | title=OneLogin Single Sign On}} | OneLogin | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML, WS-Federation, Kerberos, OAuth, OpenID | ||||||||||||||
OpenAthens LA{{Cite web | url= http://www.eduserv.org.uk/identity-access/products/openathens-la | title=OpenAthens LA}} | eduserv | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | | ||||||||||||||
OpenAthens SP{{Cite web | url= http://www.eduserv.org.uk/identity-access/products/openathens-sp | title=OpenAthens SP}} | eduserv | {{Proprietary|Commercial}} | |
| | | | | | {{ya}} | ||||||||||||||
Open Select{{Cite web | url= http://www.openaselect.org | title=OpenASelect}} | OpenASelect.org | {{Open source|OSS}} | |
| | | {{ya}} | | | |OAuth (project continues as asimba) | ||||||||||||||
Optimal IdM VIS Federation Services{{Cite web | url= http://optimalidm.com/our-products/virtual-identity-server-federation-services/ | title= Optimal IdM VIS Federation Services}} | Optimal IdM | {{Proprietary|Commercial}}
| {{ya}} | | {{ya}} | | | | {{ya}} | {{ya}} | | | {{ya}} | | | {{ya}} + Proxy, SSO |WS-Federation, WS-Trust, SAML 1.x, SAML 2.0, OAuth2, OpenID Connect, SCIM, Facebook, Twitter, LinkedIn, Google, IWA, X509, Kerberos, LDAP, Office 365, RADIUS, MFA (Push, SMS, Email, Voice, TOTP, U2F, Radius) | |||||||||||||||
Oracle Identity Federation 11g{{Cite web | url= http://www.oracle.com/technetwork/middleware/id-mgmt/index-084079.html | title= Oracle Identity Federation 11g}} | Oracle | {{Proprietary|Commercial}}
| {{ya}} | | {{ya}} | | | | {{ya}} | | | | {{ya}} | | | {{ya}} |WS-Federation, SAML 1.x, SAML 2.0, OpenID 2.0 | |||||||||||||||
Pega 7 Platform{{Cite web | url= http://www.pega.com/products/pega-7 | title=Pega7| date=15 September 2020}} | Pegasystems Inc. | {{Proprietary|Commercial}}
| | | {{ya}} | {{ya}} | | | {{ya}} | | | | | | | {{ya}} |SAML 2.0, OAuth, WS-Trust, LDAP | |||||||||||||||
PhoneFactor{{Cite web | url= https://www.phonefactor.com/ |title= PhoneFactor}} | PhoneFactor, Inc | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | | | |||||||||||||||
PicketLink{{Cite web | url= http://www.jboss.org/picketlink |title= PicketLink}} | JBoss Community | {{Open source|OSS}} | |
|OpenID, A-Select, CAS, XACML | ||||||||||||||
PingFederate{{Cite web | url= https://www.pingidentity.com/products/pingfederate/ | title=PingFederate}} | Ping Identity | {{Proprietary|Commercial}}
| | {{ya}} | | {{ya}} | | | | | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, WS-Federation, WS-Trust, WS-Security, OAuth, OpenID Connect, OpenID, SCIM, Facebook, Twitter, LinkedIn, Google, Windows Live, Kerberos, IWA, X.509, LDAP, RADIUS, 3rd Party MFA | |||||||||||||||
Plurilock AI{{Cite web | url= https://plurilock.com/products/ai-cloud/ | title=Plurilock AI Cloud}} | Plurilock | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, FIDO2, OTP, DEFEND{{Cite web | url= https://plurilock.com/products/defend/ | title=DEFEND Continuous Authentication}} | |||||||||||||||
PortalGuard{{Cite web | url= http://www.portalguard.com | title=PortalGuard}} | PistolStar, Inc. | {{Proprietary|Commercial}}
| | | | | | | | | | | {{ya}} | | | {{ya}} |SAML 2, LDAP v3, XML-DSIG, SSO Middleware | |||||||||||||||
RSA Federated Identity{{Cite web|url=http://www.emc.com/security/rsa-identity-and-access-management/rsa-federated-identity-manager.htm|title=RSA Federated Identity Manager}} | RSA | {{Proprietary|Commercial}}
| | {{ya}} | | {{ya}} | {{ya}} | | | | | | | | | |Facebook, OpenID, LinkedIn, Twitter, Windows Live | |||||||||||||||
SAASPASS
|SAASPASS |{{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, LDAP | ||||||||||||||||
Safewhere*Identify{{Cite web | url= http://safewhere.com/product/safewhere-identify| title=Safewhere*Identify}} | Safewhere | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 2.0, WS-Federation, WS-Trust, OAuth 2.0, multi-factor, OpenID Connect, Facebook, LinkedIn, Twitter, LiveID, Google, LDAP | ||||||||||||||
SailPoint IdentityNow{{Cite web | url= https://www.sailpoint.com/products/identitynow/ | title=SailPoint IdentityNow}} | SailPoint | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, OAuth2, Kerberos, WS-Federation | ||||||||||||||
Samanage{{Cite web | url= http://www.samanage.com/products/integration.html| title=Samanage}} | Samanage | {{Proprietary|Commercial}} | | {{ya}}
| | | | | | | Enterprise-to-cloud SSO Middleware | ||||||||||||||
SATOSA{{Cite web | url= https://github.com/SUNET/SATOSA| title=Github/SATOSA| website=GitHub| date=25 October 2021}} | SATOSA | {{Open source|OSS}} | | {{ya}}
| | | | | | | Proxy between SAML2, OpenID Connect and OAuth2 | ||||||||||||||
SecureAuth{{Cite web | url= https://www.secureauth.com | title=SecureAuth}} | SecureAuth Corp. | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}}
| | | | {{ya}} | | | {{ya}} | 2-Factor, IBM LTPA, Facebook, Google, LinkedIn, Microsoft FBA, Microsoft IWA, OAUTH, OpenID, OpenID Connect, SAML 1.1, SAML 2.0, Twitter, WebServices, Windows Live, X.509v3, Yahoo | |||||||||
SecureSSO{{Cite web | url=http://www.surepassid.com/ | title=SurePassID}} | SurePassID | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |WS-Federation, WS-Trust, SAML 2.0, OAuth2, OpenID Connect, O365, SCADA - cloud & on-prem | ||||||||||||||
Shibboleth | Internet2 | {{Open source|OSS}} | |
| {{ya}} | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0 | ||||||||||||||
SimpleSAMLphp{{Cite web | url= http://simplesamlphp.org | title=SimpleSAMLphp}} | UNINETT AS | {{Open source|OSS}}
| | {{ya}} | | {{ya}} | |
| | | | | |OpenID, A-Select, CAS, WS-Federation and OAuth, Facebook, LinkedIn, Twitter, Windows Live, SAML 2 | ||||||||||||||
Smartsignin{{Cite web | url=https://www.perfectcloud.io/smartsignin | title=Smartsignin Single Sign-on}} | PerfectCloud | {{Proprietary|Commercial}} | |
| | | {{ya}} | | | {{ya}} |SAML 2.0, SAML 1.0, Google, Microsoft365, LDAP, WS-Federation | ||||||||||||||
SMS PASSCODE Multi-factor Authentication{{Cite web | url= http://www.smspasscode.com/what-we-do/multi-factor-authentication/ | title=SMS PASSCODE}} | SMS PASSCODE | {{Proprietary|Commercial}} | |
| | | | {{dunno}} | | | | | ||||||||||||||
SSO EasyConnect{{Cite web | url= http://www.ssoeasy.com/enterprise-sso | title= SSO EasyConnect}} | SSO Easy | {{Proprietary|Commercial}} | |
| | {{ya}} | | | {{ya}} | | ||||||||||||||
[https://www.ssogen.com/ SSOgen]
|SSOGEN Corporation |{{Proprietary|Commercial}} | | | | | | | | | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, OAuth2, OpenID Connect, OpenID Provider, RADIUS, LDAP, Multi Factor Authentication. Cloud SSO Solution for enterprises to protect on-premise applications such as [https://www.ssogen.com/oracle-ebs-sso-integrations/ SSOgen for Oracle EBS], [https://www.ssogen.com/peoplesoft-sso/ SSOgen for PeopleSoft], [https://www.ssogen.com/oracle-jde-sso/ SSOgen for JDE], and [https://www.ssogen.com/sap-webgui-sso/ SSOgen for SAP], with a web server plug-in and Cloud SaaS applications with SAML, OpenID Connect integrations. | |||||||||||||||||
Symlabs Federated Identity Suite{{Cite web | url=http://symlabs.com/products/federated-identity-suite | title= Symlabs Federated Identity Suite}} | Symlabs | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | | {{ya}} | | | | |OpenID, A-Select, CAS, WS-Federation and OAuth | |||||||||||||||
Symplified{{Cite web | url=http://www.symplified.com/features/| title=Symplified}} | Symplified | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | | | {{ya}} | | | {{ya}} |SAML 1.1, SAML 2.0, WS-Federation, OpenID, OAuth, XACML, IBM LTPA, Microsoft IWA, 2-Factor, Facebook, Google, Twitter, ABAC / context-based AC | |||||||||||||||
Tivoli Federated Identity Manager{{Cite web | url=http://www-03.ibm.com/software/products/en/federated-identity-mgr/ | archive-url=https://web.archive.org/web/20131115021922/http://www-03.ibm.com/software/products/en/federated-identity-mgr | url-status=dead | archive-date=November 15, 2013 | title=Tivoli Federated Identity Manager| date=9 November 2020}} | IBM | {{Proprietary|Commercial}}
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | {{ya}} | |WS-Federation, OpenID, Liberty, InfoCard, Microsoft CardSpace | ||||||||
TrustBind{{Cite web | url= http://www.ntts.co.jp/products/trustbind/ | title=TrustBind/Federation Manager}} | NTT Software Corp | {{Proprietary|Commercial}}
| {{ya}} | | {{ya}} | | {{ya}} | {{ya}} | {{ya}} | | | {{ya}} | | | | |OpenID, ID-WSF | |||||||||||||||
TrustBuilder{{Cite web | url= http://www.trustbuilder.be | title=TrustBuilder}} | SecurIT | {{Proprietary|Commercial}} | |
| | | {{ya}} | {{ya}} | | {{ya}} |SAML 2.0, OAuth 2.0, OpenID Connect, Kerberos | ||||||||||||||
Trustelem{{Cite web|url=https://www.trustelem.com/cloud-sso|title=Trustelem Cloud SSO {{!}} Active Directory and multi-factor authentication|website=www.trustelem.com|language=en|access-date=2017-05-15}}
|Trustelem |{{Proprietary|Commercial}} | |
| | | {{ya}} | | | |SAML 2.0, OpenID Connect, WS-Fed, OAuth 2.0, Integrated Windows Authentication, Kerberos, Active Directory, LDAP, FIDO U2F. | ||||||||||||||||
USP Secure Entry Server{{Cite web | url= http://www.web-access-management.com/ | title=USP Secure Entry Server}} | United Security Providers | {{Proprietary|Commercial}} | |
| | | {{ya}} | {{ya}} | | {{ya}} |SAML 2.0, SAML 1.0, Kerberos, NTLM, LDAP, RADIUS, RSA, SuisseID, RBAC, SSO, Tomcat Authenticator, IIS ISAPI Filter, mTAN, PKI/X.509, Reverse Proxy, Multi-Factor, SOAP/REST Connectors, WebService Security, Office365, GoogleApps | ||||||||||||||
Weblogic | Oracle | {{Proprietary|Commercial}} | |
| | | | | | {{ya}} | | ||||||||||||||
WSO2{{Cite web | url= http://wso2.com/products/identity-server/ | title=WSO2}} | wso2 | {{Open source|OSS}} | |
| | | {{ya}} | | | {{ya}} |OAuth2, WS-Trust, OpenID | ||||||||||||||
ZITADEL{{Cite web | url= https://zitadel.com/ | title=ZITADEL}}
|ZITADEL |{{Open source|OSS}} | | | | | | | | |{{ya}} | |{{ya}} | | | |SAML 2.0, OpenID Connect 1.0, OAuth 2.0, FIDO2, OTP, U2F | |||||||||||||||||
ZXID{{Cite web | url= http://zxid.org/ | title=ZXID}} | zxid | {{Open source|OSS}} | |
| {{ya}} | {{ya}} | {{ya}} | {{ya}} | | {{ya}} |ID-WSF2, XACML2, WS-Security, XML-DSIG, TAS3 |
Libraries and toolkits to develop SAML actors and SAML-enabled services
Libraries and toolkits are used by developers to integrate applications and services into SAML federations or to build their own SAML-actors like IdPs.
References
{{Reflist|30em}}
- {{cite web| url=https://www.miniorange.com/ | title=Cloud/On-Premise service platform}}