OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Subject: RE: Indexical reference problem defined


Title: RE: Indexical reference problem defined

Hi,

Very clear explanation.

 
(...some text deleted...)

 
This is precisely why many people find public key technology attractive.  "Set up as session for whoever can authenticate to you using a private key that corresponds to this public-key certificate" solves the indexical problem without the possibility of session splicing, token stealing, or similar attacks.  Furthermore, it does not remove SSO (because SSO only matters from the perspective of the human user -- they don't want to have to re-enter a password or whatever; the machine they're using can re-authenticate every second if necessary and the human user will still think they've got SSO).

The downside, of course, is that client software may be required to do the P-K authentication.

Carlisle.



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]


Powered by eList eXpress LLC