  • From: "Scott Cantor" <>
  • To: "'Giuseppe Sarno'" <>
  • Date: Thu, 10 Nov 2005 14:34:00 -0500
> it will probably take sometime to digest this, but you gave 
> me some good thoughts and material to go through.
> It looks like this is an important feature in SAML.

It's an important feature, but also a very dangerous one. Using it amounts
to constructing a security protocol involving the assertion, and if you (not
meaning you specifically) don't think you're capable of doing that safely,
you're better off looking at other profiles like, say, Liberty WSF, for
using SAML to do advanced things.

-- Scott

