← Prev in month ← Prev in thread

Referencing Saml Assertion from it's enveloped signature (Wss Saml Token Profile vs Saml 1.1 Core spec)

From
Emil Marceta <>
Date
2005-01-13T21:07:56+00:00
ID
Thread
Referencing Saml Assertion from it's enveloped signature (Wss Saml Token Profile vs Saml 1.1 Core spec)
This is about assertion enveloped signatures in Saml assertions in 
SOAP wsse:Security header.

The (Wss Saml Token Profile) specifies the <wsse:SecurityTokenReference>
as a way of referencing the the SAML assertion, while the SAML 1.1 core 
spec menitions direct URI reference such as
<ds:Reference URI="#SamlAssertion-3e42fde8b68fbbe411e01ca9d0fdd47e"> 

Should both flavors be supported when validationg the soap assertion
signature?
How are the current Wss SAML token profile implementations handling
this?

Thanks,
Emil
← Prev in month ← Prev in thread