tech · quantum risk
Is SAML Quantum Proof? Cyber Program & PQC
Verdict
SAML federation is not quantum-proof under classical XML signatures. Many long-tail enterprise apps make algorithm migration slow—inventory early.
Overview
SAML remains common in enterprises. Assertion signature validity is the trust core.
XML signature complexity also creates classical pitfalls; quantum adds algorithm migration pressure on top.
Program inventory focus: Legacy enterprise apps often pin classical SAML IdP certs for years. Typical classical surfaces: XML signatures on assertions; IdP signing certs. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: XML signatures on assertions, IdP signing certs
- Hash: XML canonicalization and digests
- Public-key exposure: Legacy enterprise apps often pin classical SAML IdP certs for years.
What breaks
- Static IdP certs in hundreds of SPs
- No staging for cert rollover
Mitigations
- Federation inventory
- Rollover runbooks and dual-cert windows
- Prefer modern stacks with agility for new apps
FAQ
Move everything to OIDC for quantum?
Helpful classically for modern apps; quantum still needs algorithm plans either way.
Encryption of assertions?
Confidentiality and integrity both matter; document algorithms for each.
Key concepts (technical dictionary)
Terms used on this page — open a definition: