Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring Security SAML relying party: align registration, ACS and metadata

Last updated: 1 Oct 20264 min read
tutorial
IntermediateBy AITrove Editorial

A SAML relying-party registration binds service-provider settings to an asserting party and its trust material.

Treat metadata as a protocol contract

A corporate identity provider posts a response to the service provider's assertion consumer service, or ACS. Spring Security resolves a RelyingPartyRegistration to validate that exchange. Its default login processing path includes /login/saml2/sso/{registrationId}; metadata can be published per registration. The IdP and app must agree on the issuer, ACS and credentials. Forwarded host handling matters when a proxy changes the public origin.

Keep tenants separate

If two employers use different IdPs, give each a distinct registration and bind the login entry point to the tenant's trusted registration. Never let a user-supplied issuer string select an arbitrary registration. Store trust material through a reviewed rotation path and verify metadata changes before activation.

Run a real protocol test

Import the service-provider metadata into a test IdP, complete one login, then change the ACS or issuer and assert failure. Repeat behind the production proxy so generated URLs use the public origin.

Implementation sketch

Java
http.authorizeHttpRequests(requests -> requests
    .requestMatchers("/saml2/metadata/**").permitAll()
    .anyRequest().authenticated())
    .saml2Login(Customizer.withDefaults())
    .saml2Metadata(Customizer.withDefaults());

Cost and verification

Each login exchanges signed XML and creates a local authenticated session. Multi-IdP setups add registration and certificate rotation work; cache only metadata according to a defined freshness policy.

Common Mistakes

  • Do not change the login processing path without updating the ACS in metadata and the IdP.
  • Do not trust an IdP solely because its issuer string looks familiar.
  • Do not expose an internal proxy host in published service-provider metadata.

Read next

Spring Security SAML validation: signatures, audience and clock window, Spring Security SAML attributes: map identity to local authority, Spring behind a proxy: trust forwarded headers only after the edge strips them.

Related boundary

Spring Security SAML logout: local session versus single logout

Check your understanding

Spring SAML trust and session quiz

spring
spring-boot
security
saml-relying-party-metadata
Storage details