Next in thread → Next in month →

RE: [saml-dev] How does an artifact issuer "authenticate" the sender of the <ArtifactResolve> message?

From
Scott Cantor <>
Date
2006-06-22T17:30:54+00:00
ID
009a01c6962a$701c3f10$
Thread
RE: [saml-dev] How does an artifact issuer "authenticate" the sender of the <ArtifactResolve> message?
> Perhaps one of the things we should do in a future release is to
> add an element in the assertion indicating how the assertion 
> was to be delivered.  This would reduce the usefulness
> of a MiTM getting an assertion as they could no longer use it 
> in a non-artifact delivery. 

Yeah, I can see how that would have been one useful aspect of the old
artifact subject confirmation, and I considered proposing to add that back
late in the process once the binding/profile split had been re-worked to my
satisfaction. If that was the primary reason for having it originally, I
missed it, sorry.

-- Scott
Next in thread → Next in month →