OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]

Subject: (PR) 15-day Public Review for SAML V2.0 Kerberos Web Browser SSO Profile Version 1.0

The OASIS Security Services (SAML) TC [1] members have produced an
updated Committee Specification Draft (CSD) and submitted this
specification for 15-day public review:

SAML V2.0 Kerberos Web Browser SSO Profile Version 1.0
Committee Specification Draft 02 / Public Review Draft 02
29 November 2011

Specification Overview:
The SAML V2.0 Kerberos Web Browser SSO Profile allows for transport of
assertions using the Kerberos subject confirmation method by standard
HTTP user agents with no modification of client software and maximum
compatibility with existing deployments. The flow is similar to
standard Web Browser SSO, but a Kerberos AP-REQ message is presented
by the user agent via the HTTP Negotiate authentication scheme and the
Kerberos GSS-API mechanism. The presentation of a valid Kerberos
AP-REQ message whose client principal name matches the principal name
given in the subject confirmation strengthens the assurance of the
resulting authentication context and protects against credential

Public Review Period:
The public review starts 5 December 2011 and ends 20 December 2011.
The specification was previously submitted for a 60-day public review
[2]. This 15-day review is limited in scope to changes made from the
previous review. Changes are highlighted in the diff-marked PDF file
included with the specification.

This is an open invitation to comment. OASIS solicits feedback from
potential users, developers and others, whether OASIS members or not,
for the sake of improving the interoperability and quality of its
technical work.

The complete package of the prose specification document and related
files are available in the ZIP distribution file at:


Additional information about the specification and the OASIS Security
Services (SAML) TC may be found at the TC's public home page:


Comments may be submitted to the TC by any person through the use of
the OASIS TC Comment Facility which can be located via the button
labeled "Send A Comment" at the top of the TC public home, or directly


Comments submitted by TC non-members for this work and for other work
of this TC are publicly archived and can be viewed at:


All comments submitted to OASIS are subject to the OASIS Feedback
License, which ensures that the feedback you provide carries the same
obligations at least as the obligations of the TC members. In
connection with this public review of SAML V2.0 Kerberos Web Browser
SSO Profile Version 1.0, we call your attention to the OASIS IPR
Policy [3] applicable especially [4] to the work of this technical
committee. All members of the TC should be familiar with this
document, which may create obligations regarding the disclosure and
availability of a member's patent, copyright, trademark and license
rights that read on an approved OASIS specification. OASIS invites any
persons who know of any such claims to disclose these if they may be
essential to the implementation of the above specification, so that
notice of them may be posted to the notice page for this TC's work.

========== Additional references:

[1] OASIS Security Services (SAML) TC

[2] 60-day public review, 16 April 2010:

[3] http://www.oasis-open.org/who/intellectualproperty.php

[4] http://www.oasis-open.org/committees/security/ipr.php
RF on RAND Terms

Best Regards,

Chet Ensign
Director of Standards Development and TC Administration
OASIS: Advancing open standards for the information society

Primary: +1 973-378-3472
Mobile: +1 201-341-1393

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]