Subject: RE: SubjectConfirmation not clear - example

> Could someone please provide a clear explanation for these 
> tags in plain english with a real example ?  That would 
> really help me out a lot !

Your best bet is probably the WSS SAML token profile (both the original and
the new SAML 2.0 compatible version), which you can get from the OASIS WSS
site. They discuss use of at least holder of key in some detail.

What you need to understand is that the precise semantics depend on the
profile. It's a building block, it isn't intended to be used without
additional specs. It's those specs you have to look at.

The SSO profiles use bearer, for example, and I don't see how that's

-- Scott

