Subject: RE: [saml-dev] SAML, trust and WS.

> as a baseline, i had something like this in mind:
> http://www.ws-i.org/deliverables/workinggroup.aspx?wg=basicsecurity

Sure. I haven't read the latest revs of that, but my understanding is it
doesn't address anything we've been talking about, only constrains some of
the basic security mechanisms and how WSS would be used. It wouldn't address
SAML token content, nor how tokens are obtained. Corrections welcome on any
of that, I'm not the expert.

> i have to say, i haven't researched the above in any real detail. 
> but at first glance, it sounds like a reasonble benchmark. what is 
> OASIS' position on what ws-i proposes?

I don't speak for OASIS, and I don't know enough about WS-I to comment about
it in any detail.

-- Scott

