wss message
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
--
[Date Index]
| [Thread Index]
| [List Home]
Subject: RE: [wss] proposed terminology addition to STP - impersonation
- From: Anthony Nadalin <drsecure@us.ibm.com>
- To: "Don Flinn" <flinn@alum.mit.edu>
- Date: Thu, 11 Mar 2004 22:33:36 -0600
ahhh, I was on "Attesting Entity"
Anthony Nadalin | work 512.838.0085 | cell 512.289.4122
"Don Flinn" <flinn@alum.mit.edu>
"Don Flinn" <flinn@alum.mit.edu>
03/10/2004 08:18 PM
|
|
Tony
I don't see any definition of impersonation in the SAML Glossary. But more to the point, the reason I asked Ron to include a definition of impersonation was that at the time he and Rich Levinson were defining a protocol in the SAML profile, which used impersonation . This I felt would lead users to assume that using the impersonation capability would be equivalent to using delegation, since the difference between the two is subtle to the uninitiated. In fact, the two are quite different in that in delegation the delegator should be able to say who can act as delegatees for him and to limit what activities the delegatees can perform in the delegator's name. Impersonation says that anyone can do anything in the name of the impersonated entity. However, since this addition to the specification is not being incorporated, I withdraw my request.
Don

[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
--
[Date Index]
| [Thread Index]
| [List Home]