OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [saml-dev] SAML2HoKAP question


Tom Scavo wrote on 2009-05-19:
> Add a <saml:NameID> element to the <saml:SubjectConfirmation> element,
> you mean?  This is useful in cases where the presenter is not the
> attesting entity.  The Shib-uPortal use case is one such example, I
> think:
> 
> https://spaces.internet2.edu/display/ShibuPortal/Home

It is, though in retrospect the need to signal more strongly that delegation
is happening led to my proposal for a condition rather than the very limited
approach of an optional element without any mandatory processing rules.

For situations where the possibility of delegation is just a given, using
the confirmation might be ok.

> Scott requested that this requirement be included in the profile, so
> I'm sure he can provide more detail.

If I said something, I don't recall it, but the basic definition there is
just what's in core anyway, it's not unique to this profile. It's
confirmation method agnostic.

-- Scott




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]