OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

imi message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [imi] Hopefully last change to the IMI spec before producing aCommittee Draft


I don't think that wording is right or conveys what the issue brought up over a year ago at various meetings, as user-specific information as this can mean static well known user-specific information which is not what we want, what we want is entropy from the user/client (and user is not right term either as may not have a user may have a process/client/device, etc)

Anthony Nadalin | Work 512.838.0085 | Cell 512.289.4122

Inactive hide details for Mike Jones ---02/18/2009 06:00:38 PM---In reviewing the IMI spec draft, one of our security experts iMike Jones ---02/18/2009 06:00:38 PM---In reviewing the IMI spec draft, one of our security experts identified a non-protocol security issue in the present draft that


From:

Mike Jones <Michael.Jones@microsoft.com>

To:

"imi@lists.oasis-open.org" <imi@lists.oasis-open.org>

Date:

02/18/2009 06:00 PM

Subject:

[imi] Hopefully last change to the IMI spec before producing a Committee Draft





In reviewing the IMI spec draft, one of our security experts identified a non-protocol security issue in the present draft that I believe we should address. Fortunately, it’s a very simple and, I suspect, non-controversial change to fix.

The proposed change in Section 3.3.4 (Client Pseudonym) is to change the sentence: to:
Here’s an explanation of why this change is a good idea…

I’ve also discussed this change with John Bradley, who was the one who pointed out that it was a bad idea to use the Client Pseudonym value verbatim in the first place, and he agrees with this additional to our guidance to Identity Providers.

Talk to all of you in the morning!

-- Mike



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]