OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

wss message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: prooposed changed to SAML token profile (editorial) and for issue 261


lines 265,331,332,349,357,372,373,385,392,422,429458,494,495,519,
660,661,672,758,765,801,802,812
.s/wsu:id/wsu:Id/

change in recommended processing rules for sender-vouches in table 
beginning at line 551.

.s/In the typical case (that is, where the assertion authority has not 
bound a confirmation key to the subject statements) t/T/

related change beginning at line 695

> In the typical case, where the assertion authority has NOT securely 
> bound a confirmation key in the sender-vouches 
> <saml:SubjectConfirmation> element, the attesting entity MUST also 
> protect the vouched for subject statements against unauthorized 
> modification.

The attesting entity MUST also cause the vouched for subject statements 
(as necessary) and their binding to
the message contents to be protected such that unauthorized modification 
can be detected.





[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]