Rob,
Thanks for
your comments. The only area requiring discussion
are your
comments about inter-site transfer URL.
You are
correct in observing that the browser profile does not
"require"
this URL to be shared between partners. It is enough
if
destination
sites publish an application URL (resource TARGET) and
the artifact
receiver URLs to source sites.
While the
demo showcases the profile, it also "clothes" it in a
business
flow. This is
where case (4) of section 1.5 fits in. It suggests that if a
user directly
visits a URL (TARGET) at a content-site, they should be shown a set of
portal inter-site transfer URLs (presumably with TARGET on the query
string) . The user can select one of the transfer URLs,
access the appropriate portal
and be re-directed back to the content
site with an assertion.
Basically, we
are combining the browser profile, with an additional sequence of
HTTP steps. This sequence is well
known (and non-proprietary) and demonstrates the utility of the
profile.
I am open to
removing step (4), though there was previous discussion
which
suggested
interest in this direction. Let me know what you think.
Are other
vendors planning to support step (4)?
-
prateek
-----Original Message-----
From: Philpott, Robert
[mailto:]
Sent: Thursday, May 02, 2002 4:29
PM
To: 'Mishra, Prateek';
Subject: RE: [saml-dev]
draft-catalyst-interop-plan-01
I've embedded a bunch
of comments/suggested changes using Word edit tracking...
Rob
Philpott
RSA
Security Inc.
The
Most Trusted Name in e-Security
Tel:
781-515-7115
Mobile:
617-510-0893
Fax:
781-515-7020
mailto:
-----Original
Message-----
From: Mishra,
Prateek [mailto:]
Sent: Friday, April 26, 2002 6:40
PM
To:
Subject: [saml-dev]
draft-catalyst-interop-plan-01
Please comment, I may have missed
an existing suggestion or amendment.
-
prateek