Next in thread → Next in month →

Re: [saml-dev] saml Subject

From
Yuji Sakata <>
Date
2002-11-29T00:52:19+00:00
ID
Thread
Re: [saml-dev] saml Subject
Hi,

> A) NameIdentifier - There's a standard URI reference (like
> #emailAddress) describe the format of an LDAP DN ? If not, can i define
> one without go out of specification boundary ?

SAML spec (cs-sstc-core-01) 2.4.2.2 says,
"... The interpretation of the NameQualifier ,and  NameIdentifier's 
content in the case of a Format not specified in this document, are left 
to individual implementations."
So, you can define the format of an LDAP DN as , for example, "urn:ietf:
rfc:2253"

> B) The element SubjectConfirmation could have the ConfirmationMethod as
> a sort of "LDAPBind" and SubjectConfirmationData as the password ?
Yes , see 2.4.3.3.
However the AuthenticationAssertion is not data to authenticate a 
subject but data proving the subject in the assertion is authenticated.
So it might be inadequate that SubjectConfirmationData includes password 
itself.

Regards,
----------------------------------------------
NTT Data Corporation
Yuji Sakata
E-Mail: 
----------------------------------------------
Next in thread → Next in month →