OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [security-services] JIRA SECURITY-6 PE: Conflict with core in SSO profile on returning error Responses to SP


> Why mention a specific error condition at all? How about just:
> 
> "Identity Provider implementations MUST/SHOULD support the issuance of
> <saml2p:Response> messages (with appropriate status codes) in the event of
> an error condition, provided that the user agent remains available and an
> acceptable location to which to deliver the response is available."

I was concerned that "error condition" would be so broad as to reintroduce
the same set of questions about whether to respond, but if you think the
rest of the text is clear enough about that, I'm ok with it.

-- Scott




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]