A successful XML parse is not authentication; the response and assertion must pass trust and time checks.
Spring Security SAML validation: signatures, audience and clock window
Validate the complete assertion
A response can contain a NameID and attributes yet still be untrusted. Spring Security's SAML provider uses the relying-party registration to verify credentials and protocol constraints. The asserted audience, destination and time conditions must match the intended service provider. Keep clocks synchronized, and set only the skew needed for measured drift.
Rotate trust deliberately
When the IdP changes its signing certificate, overlap old and new verification credentials for a bounded migration if the IdP supports it. Fetching unsigned metadata over an untrusted channel and accepting whatever key appears is not a rotation policy. The registration is the place where that trust decision becomes concrete.
Test rejection paths
Use a test IdP or signed fixtures to submit an expired assertion, altered signature, wrong audience and response for another registration. All must fail before a session or authority is created. Also test a small positive skew; do not silently widen the window until failures disappear.
Implementation sketch
// Operational invariant, not a custom parser:
// accepted = trusted signature && expected audience
// && expected destination && valid time window
// && matching relying-party registrationCost and verification
Signature verification and XML processing add CPU to login requests. Keep metadata and key lookup bounded, and rate-limit failed sign-ins without weakening validation.
Common Mistakes
- Do not consider a parsed NameID proof of authentication.
- Do not disable signature checks to accommodate a certificate rollout.
- Do not use a large clock skew to hide unsynchronized hosts.
Read next
Spring Security SAML relying party: align registration, ACS and metadata, Spring Security SAML attributes: map identity to local authority, Spring Security 401 versus 403: authentication and access are separate failures.
Related boundary
Spring SAML certificate rollover: overlap trust without accepting unknown keys
