[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Subject: RE: [saml-dev] ConfirmationData?
Folks,
this is an
issue. We do not use confirmation data, nor do we check for it
in
the artifact
case.
Nowhere in
the artifact browser profile description is there a requirement that
ConfirmationData be used. Indeed, one key requirement in
developing the artifact
profile was
that there be NO relationship between the artifact and the assertion itself. By
placing
the artifact
in the assertion (as conf data) this requirement is violated (however weakly).
The
relationship between the artifact and the assertion is established via bilateral
authentication
between
source and destination sites. There is no other relationship
required.
-
prateek
|
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Powered by eList eXpress LLC