security-services message
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
--
[Date Index]
| [Thread Index]
| [List Home]
Subject: Comments on profiles-2.0-cd-01
- From: Paul Madsen <p.madsen@entrust.com>
- To: "'security-services@lists.oasis-open.org'" <security-services@lists.oasis-open.org>
- Date: Mon, 30 Aug 2004 13:33:54 -0400
- Section 4.1.4.2 - Line 547 states 'any
such authentication statements MUST include a
SessionIndex attribute to
enable per-session logout requests by the service provider.'
a) refers to SessionIndex
attribute rather than element
b) Why not explicitly state
that the authority MUST use unique values for subsequent values of
<SessionIndex> to the same SP rather than express the
requirement in a roundabout
way
- Section 4.4.3.4 - Line 1239 -
Reference to Section 4.4.4.1 should be to Section 4.4.4.2
- Section 4.4.3.5 - we provide very
little guidance on how the IDP should (or shouldn't) propogate error information
from Session Participants to the original initiating SLO SP. Line 1242 states
'the identity provider MUST respond to
the original request with a <LogoutResponse> containing
an appropriate
status code to complete the SAML protocol exchange'
but what is an 'appropriate status
code'? Is it 'Success' if the IDP received 'Success' from 2 of the 3 SP's it
sent <LogoutRequest>s to? Is this
'implementation dependent'?
Given that more than one SP could return
different second-level <StatusCode>s to the IDP, is there a need for
a new generic code URI for the IDP to use in its response to the original
SP, e.g.
urn:oasis:names:tc:SAML:2.0:status:GroupSLOError
The
schema as is doesn't support the IDP sending them all on.
- Section 7.4.2 - Line 1585 - makes
reference to Section 2.3.3 as the appropriate section
for
<EncryptedID> in [SAMLCore]. The actual relevant section number in Core is
2.2.3
Paul
-----------------------------------------------------------------
Paul
Madsen
p: 613-270-2632
c: 613-799-2632
Entrust
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
--
[Date Index]
| [Thread Index]
| [List Home]