Learning outcomes
- Separate transport, authentication, authorization, token, and application roles.
- Validate issuer, audience, keys, certificates, redirect binding, correlation, and time.
- Apply current security profiles and mark drafts, obsolete protocols, and local extensions.
- Build negative tests for downgrade, substitution, replay, confusion, and stale metadata.
Scenario
A protected application receives a Pomerium identity assertion after OpenID Connect sign-in. The team must identify which system issued each object, which audience applies, how keys rotate, and which claims the application can trust.
Ordered learning units
HTTP Semantics
HTTP semantics define request methods, targets, fields, responses, status codes, authorities, and intermediary behavior.
Separate DNS from service identity
Trace resolution, routing, certificate names, endpoint authentication, and failover without treating DNS as identity.
HTTPS and TLS
Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.
Trace TLS 1.3 through an access system
Trace TLS 1.3 authentication, key establishment, record protection, termination, and early-data risk across an access path.
Validate an X.509 certificate path
Validate X.509 paths, service names, key usage, constraints, time, and revocation without expanding the trust boundary.
OAuth 2.0
Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.
Run OAuth authorization code with PKCE
Bind an OAuth authorization code to one client transaction and reject code theft, injection, mix-up, and redirect abuse.
OAuth Client Credentials Grant
The client credentials grant issues authority to a confidential client acting for itself, not for a human user.
Token Issuer and Audience
Accept a token only from a trusted issuer and only at the resource audience for which the token was issued.
Security Time and Freshness
Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.
OAuth Resource Indicator
An OAuth resource indicator identifies the protected resource for which a client requests an access token.
Validate JOSE objects safely
Separate JWT claims, JWS signatures, JWE encryption, and JWK key data and apply a fixed validation policy.
Operate token status and revocation
Separate token expiry, introspection, revocation, session termination, and replay response and measure the effective denial time.
Validate an OpenID Connect sign-in
Trace OpenID Connect sign-in and validate issuer, client, redirect, state, nonce, ID token, and access-token boundaries.
Trace a SAML federation flow
Trace identity provider, service provider, metadata, bindings, assertions, signatures, audience, correlation, and logout.
SCIM Provisioning
Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.
Evaluate WebAuthn and passkeys
Trace WebAuthn registration and authentication across relying party, browser, authenticator, origin, and user verification.
SSH Protocol
SSH authenticates a server and client, then multiplexes sessions, commands, and forwarding channels over one transport.
Authorize HTTP tunnels and upgrades
Place authentication and authorization around WebSocket upgrade, HTTP CONNECT, CONNECT-UDP, and long-lived tunnels.
Operate protocol versions and deprecations
Inventory protocol profiles, detect use, migrate consumers, and remove obsolete versions without permanent compatibility paths.
Evaluation questions
- Which exact specification revision and profile does each system implement?
- Which values come from trusted local configuration instead of an untrusted message?
- Which negative objects prove substitution, replay, downgrade, and cross-context use fail?
Completion conditions
- Document one end-to-end protocol flow with exact roles, messages, validation, and trust sources.
- Run a negative corpus that changes one security-relevant field or state at a time.
