Scott Cantor
- Did most of the technical editing of the SAML 2.0 specifications at OASIS
- Project architect for Shibboleth and maintainer of its Service Provider software
- Long-running contributor to InCommon and Internet2 middleware
Bio
Scott Cantor did most of the technical editing of the SAML 2.0 specifications at OASIS and has been the architect and long-term maintainer of Shibboleth, the open-source SAML implementation that research and education federations run on. He splits his time between the Shibboleth Consortium, InCommon, Internet2 middleware work, and running single sign-on for Ohio State.
Profile built from public OASIS, consortium, and university records.
Where their work shows up
SAML is often written off as legacy, which ignores that it still carries most enterprise and nearly all research-and-education federation, at a scale of thousands of institutions with no common vendor. Shibboleth is why that federation exists without one, and the precision of the SAML 2.0 text is why implementations from different decades still interoperate. See SAML vs OIDC for how to choose between them today, and the SAML 2.0 deep-dive.
Related on Start with Identity
- CVECisco SAML 2.0 mixes authorization domains
Cisco's SAML 2.0 implementation did not keep authorization domains apart. A token or assertion meant for one domain could authorize in another. May 2024. The pr
- CVEFortiCloud SSO SAML bypass on FortiOS, FortiProxy, FortiSwitchManager
A crafted SAML message bypasses FortiCloud SSO (CWE-347). Arctic Wolf saw malicious logins three days after disclosure. CISA added it to KEV on 16 December 2025
- CVEFortinet follow-on SSO SAML bypass after the 59718 patch
A second FortiCloud SSO SAML bypass that hits devices already patched for CVE-2025-59718 and CVE-2025-59719. Actively exploited. CISA guidance 28 January 2026.
- BlogFortinet's January SSO bypass hit boxes already patched for December's SAML bug
CVE-2026-24858 is the follow-on FortiCloud SSO SAML bypass. Devices patched for CVE-2025-59718 and 59719 were still exploitable. Actively exploited. CISA guidan
- GlossaryIdentity Federation
A trust relationship between identity providers and service providers that lets users authenticate once at their home IdP and access applications at the other p
- GlossaryIdentity Provider (IdP)
A system that authenticates users and issues assertions or tokens vouching for their identity to other applications. In federated single sign-on, the identity p