Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 8169117
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: June 6, 20262026-06-06T20:45:02+00:00 2026-06-06T20:45:02+00:00

So, I see there are few different implementation profiles for SAML 2.0 sp-initiated configurations:

  • 0

So, I see there are few different implementation profiles for SAML 2.0 sp-initiated configurations:

  1. POST-POST
  2. Redirect-POST
  3. Artifact-POST
  4. POST-Artifact
  5. Redirect-Artifact
  6. Artifact-Artifact

What are the advantages of each? We are implementing an sp-initiated approach and from an end-user perspective, the experience of each profile seems to be the same, but I’m concerned about the security implications. Is one more secure than the other?

BTW…We are implementing OpenAM as our IdP and SimpleSAMLphp as our SP library. If you know that setup will only support a specific profile, I’d love to know that too.

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-06-06T20:45:04+00:00Added an answer on June 6, 2026 at 8:45 pm

    Security for all of the bindings are similar if implemented correctly. The main considerations are:

    Redirect – may not be ideal for cases where a large message is being sent. Browsers have different limitations on maximum URL size. For something like an Authetication Reqest – it’s generally appropriate.

    POST – better for large message sizes like Authentication Response. Most implementations use JavaScript to auto submit these. If your users are using modern browsers with JavaScript enabled you are probably ok.

    Artifact – intended for old, typically mobile, browsers. What is sent via the browser is minimal – just a small random artifact used by the backend to resolve the SAML message. That said – it relies on your backend system being able to call out to the other party. Some network security architectures dont allow this.

    Consult the SAML 2.0 Conformance doc for guidelines. For example Redirect is not allowed for the SSO response. Most commonly you will see Redirect-POST being used in deployments. I’m sure your chosen products will support these bindings.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

I see quite a few different issues with the alert window and new lines.
There are a few stored procedures that routinely get called by a few different
I'm trying to translate my Mac app into a few different languages. There are
I see there are techniques available to have deep models in Backbone, but how
I see there are several posts regarding Cannot set Property and I'm still struggling
I see there is a question here but there is no definite answer. Has
I see there is version 1.5 and 3.0 beta , but I can't seem
I see there are BN_CLICKED and BN_DBLCLK notification messages for a button control. but
I see there are lot's of examples in Ext JS where instead of actually
I see there is a API call for Frienships/Show, but I am not sure

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.