Roland Hedberg
- Wrote pysaml2, the Python SAML 2.0 implementation shipped in many distributions
- Wrote pyoidc, a certified Python OpenID Connect implementation
- Built the OpenID Connect conformance test suite work and IdP proxy for Swedish federation
Bio
Roland Hedberg has worked in the research and education community since 1987. He wrote pysaml2, the Python SAML 2.0 implementation still packaged by many operating systems, and later pyoidc, a certified Python OpenID Connect implementation, alongside work on the OpenID Connect conformance test suite and an identity provider proxy for Swedish federation.
Profile built from public project, certification, and university records.
Where their work shows up
Research and education federation runs on open-source code written by people inside it, because no vendor was going to serve thousands of universities with no common budget. pysaml2 and pyoidc are that code for the Python ecosystem, and the conformance test work matters just as much: certification is what turns "we implemented the spec" into something a federation operator can verify. See SAML vs OIDC and the standards deep-dives.
Related on Start with Identity
- CVECisco SAML 2.0 mixes authorization domains
Cisco's SAML 2.0 implementation did not keep authorization domains apart. A token or assertion meant for one domain could authorize in another. May 2024. The pr
- CVEFortiCloud SSO SAML bypass on FortiOS, FortiProxy, FortiSwitchManager
A crafted SAML message bypasses FortiCloud SSO (CWE-347). Arctic Wolf saw malicious logins three days after disclosure. CISA added it to KEV on 16 December 2025
- CVEFortinet follow-on SSO SAML bypass after the 59718 patch
A second FortiCloud SSO SAML bypass that hits devices already patched for CVE-2025-59718 and CVE-2025-59719. Actively exploited. CISA guidance 28 January 2026.
- BlogFortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidan
- GlossaryIdentity Federation
A trust relationship between identity providers and service providers that lets users authenticate once at their home IdP and access applications at the other p
- GlossaryIdentity Provider (IdP)
A system that authenticates users and issues assertions or tokens vouching for their identity to other applications. In federated single sign-on, the identity p