saml-dev message

Subject: Encryption Question on Attribute Sharing Profile

Rick, hi. In several locations you talk about the following:
"MAY use a previously established symmetric key"
Can you elaborate on this. Do you mean:
- a symmetric key established out of band?
- a symmetric key that is present somewhere in the current xml msg (so only one EncryptionKey element is necessary for each SAML msg)?
- a symmetric key that was present in some previous SAML msg (could have been hours/days ago); hence placing a persistence requirement on the receiving service?
The next paragraph(s) talk about changing the symmetric key. Does this imply, if changed, it needs to be persisted by the receiving provider from now on. Or will the changed symmetric key be send each time afterwards until it is changed out of band?
Thanks, Tom.

