Skip to main content

Validate identity and access protocols

Validate TLS, X.509, OAuth, OpenID Connect, JOSE, WebAuthn, metadata, token, and version boundaries.

Learning outcomes

  • Separate transport, authentication, authorization, token, and application roles.
  • Validate issuer, audience, keys, certificates, redirect binding, correlation, and time.
  • Apply current security profiles and mark drafts, obsolete protocols, and local extensions.
  • Build negative tests for downgrade, substitution, replay, confusion, and stale metadata.

Scenario

A protected application receives a Pomerium identity assertion after OpenID Connect sign-in. The team must identify which system issued each object, which audience applies, how keys rotate, and which claims the application can trust.

Ordered learning units

  1. Concept

    HTTP Semantics

    HTTP semantics define request methods, targets, fields, responses, status codes, authorities, and intermediary behavior.

  2. Concept

    HTTPS and TLS

    Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.

  3. Concept

    OAuth 2.0

    Learn how OAuth 2.0 separates clients, authorization servers, resource servers, scopes, tokens, PKCE, and current OAuth 2.1 guidance.

  4. Concept

    Token Issuer and Audience

    Accept a token only from a trusted issuer and only at the resource audience for which the token was issued.

  5. Concept

    Security Time and Freshness

    Use clocks, expiries, nonces, sequence, versions, and replay state without treating wall time as a complete ordering or trust source.

  6. Concept

    OAuth Resource Indicator

    An OAuth resource indicator identifies the protected resource for which a client requests an access token.

  7. Guide

    Trace a SAML federation flow

    Trace identity provider, service provider, metadata, bindings, assertions, signatures, audience, correlation, and logout.

  8. Concept

    SCIM Provisioning

    Provision and deprovision accounts and groups without confusing lifecycle synchronization with authentication federation.

  9. Guide

    Evaluate WebAuthn and passkeys

    Trace WebAuthn registration and authentication across relying party, browser, authenticator, origin, and user verification.

  10. Concept

    SSH Protocol

    SSH authenticates a server and client, then multiplexes sessions, commands, and forwarding channels over one transport.

Evaluation questions

  • Which exact specification revision and profile does each system implement?
  • Which values come from trusted local configuration instead of an untrusted message?
  • Which negative objects prove substitution, replay, downgrade, and cross-context use fail?

Completion conditions

  • Document one end-to-end protocol flow with exact roles, messages, validation, and trust sources.
  • Run a negative corpus that changes one security-relevant field or state at a time.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo