AWS Security ChangesHomeSearch

AWS res: SAML IdP response Destination changed from HTTP to HTTPS

Service: res · 2026-09-29 · Security-related high

File: res/archive/release-minus-2/ug/configure-id-federation.md · Type: encryption

Summary

Updates the SAML assertion Destination example from http:// to https:// and removes a redundant 'please' in the IAM Identity Center cross-reference. The URL scheme change ensures the SAML IdP response is sent over TLS.

Security assessment

The example SAML Destination was previously plaintext HTTP, which would allow interception or tampering of authentication assertions in transit; switching to HTTPS enforces TLS for the federated authentication flow, a concrete authentication/encryption weakness being corrected.

Evidence

+          Destination="https://user-pool-domain/saml2/idpresponse"

Diff

diff --git a/res/archive/release-minus-2/ug/configure-id-federation.md b/res/archive/release-minus-2/ug/configure-id-federation.md
index 8b36f3b46..88499583e 100644
--- a//res/archive/release-minus-2/ug/configure-id-federation.md
+++ b//res/archive/release-minus-2/ug/configure-id-federation.md
@@ -11 +11 @@ Configure your identity providerConfigure RES to use your identity providerConfi
-Research and Engineering Studio integrates with any SAML 2.0 identity provider to authenticate user access to the RES portal. These steps provide directions to integrate with your chosen SAML 2.0 identity provider. If you intend to use IAM Identity Center, please see [Setting up single sign-on (SSO) with IAM Identity Center](./sso-idc.html).
+Research and Engineering Studio integrates with any SAML 2.0 identity provider to authenticate user access to the RES portal. These steps provide directions to integrate with your chosen SAML 2.0 identity provider. If you intend to use IAM Identity Center, see [Setting up single sign-on (SSO) with IAM Identity Center](./sso-idc.html).
@@ -99 +99 @@ Provide the input in the following format.
-          Destination="http://user-pool-domain/saml2/idpresponse"
+          Destination="https://user-pool-domain/saml2/idpresponse"