security-services message

Subject: Errata in ManageNameIDRequest text

I first thought this was a schema bug, because I could swear that things
were set up to enable an IdP to register a new ID with a different Format or
NameQualifier with the SP, but reading closer, the text is fairly explicit
about NewID being the NameID "content" and it rules out changing anything
else. Annoying to me, but ok.

But I think we need text explaining that if the NewID is encrypted (the
NewEncryptedID choice), that the element being encrypted is just the NewID
element and not a full NameID as in the more typical EncryptedID element.

Otherwise it gets a little ugly and it doesn't match what's in the text to
explain what to do with it.

-- Scott

