OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Subject: RE: [security-services] ISSUE: bindings-model-11: SSO Assertion'sConfirmationMethod set to SAMLArtifact?


Title: RE: [security-services] ISSUE: bindings-model-11: SSO Assertion'sConfirmationMethod set to SAMLArtifact?


>So the change to make to bindings-model-11 is to change lines 525-526 of
>bindings-model-11 to say..

>  The <saml:ConfirmationMethod> element of each assertion MUST be set
>  to the value specified in [SAMLCore] for "SAML Artifact", and the
>  <saml:SubjectConfirmationData> element MUST be present with its value
>  being the SAML_artifact supplied to obtain the assertion.

I agree that Artifact is a little different from other comfirmation methods, but it does allow you to verify that you got the Assertion you asked for.

Hal



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Powered by eList eXpress LLC