Subject: RE: [wss] proposed terminology addition to STP - impersonation

I don't see any definition of impersonation in the SAML Glossary.  But more to the point, the reason I asked Ron to include a definition of impersonation was that at the time he and Rich Levinson were defining a protocol in the SAML profile, which used impersonation .  This I felt would lead users to assume that using the impersonation capability would be equivalent to using delegation, since the difference between the two is subtle to the uninitiated.  In fact, the two are quite different in that in delegation the delegator should be able to say who can act as delegatees for him and to limit what activities the delegatees can perform in the delegator's name.  Impersonation says that anyone can do anything in the name of the impersonated entity.  However, since this addition to the specification is not being incorporated, I withdraw my request.
From: Anthony Nadalin [mailto:drsecure@us.ibm.com]
Sent: Tuesday, March 09, 2004 4:56 PM
Can't you just put a reference to the SAML Glossary in the appendix and thus not define duplicate terms ?

Donn Flinn asked that a definition of impersonation be added to the
terminology section of the SAML token profile.

I propose that the following line be added (at about line 183).

Impersonation – occurs when the attesting entity is not the subject of
the assertions.

where attesting entity is already defined as:

175 Attesting Entity – the entity that provides the confirmation
evidence that will be
used to establish the correspondence between the subject of SAML subject
statements (in SAML assertions) and SOAP message content.

