Next in thread → Next in month →

Réf. : RE: [saml-dev] AttributeQuery : why SOAPbinding ?

From
valerie.baucheAbull.net
Date
2008-11-14T09:36:30+00:00
ID
Thread
Réf. : RE: [saml-dev] AttributeQuery : why SOAPbinding ?
>Because it's an extra round trip, probably 4-6 extra RSA operations, and I

>seriously doubt that most implementations would allow for it. Of course, the

>latter is true of an extension as well at the moment.

I don't understand why you say it's an extra round trip !

In my scenario I first send an authnrequest, only for authentication.

Later in the process I need the attributes, so I need to send another request. 

So it won't take more time to send an AttributeQuery rather than an AuthRequest ! In both case there is the same number of RSA operations...

And in both case I can't be sure that another implementation would accept it...

So for me, those solutions are equivalent but it is more simple to use an AttributeQuery (with no modification in it, just using an unexpected binding) rather than a modified AuthnRequest (because I need to modifie the standard one).

Valérie BAUCHE

Ingénieur en développement de solutions de sécurité

Bull, Architect of an Open World TM

Tél : 02 41 93 57 09

http://www.bull.com

Bull recrute : http://www.bull.fr/emploi 

Ce message contient des informations confidentielles, couvertes par le secret professionnel ou réservées exclusivement à leur destinataire. Toute lecture, utilisation, diffusion ou divulgation sans autorisation expresse est rigoureusement interdite.

Si vous n'en êtes pas le destinataire, merci de prendre contact avec l'expéditeur et de détruire ce message. 

This e-mail contains material that is confidential for the sole use of the intended recipient. Any review, reliance or distribution by others or forwarding without express permission is strictly prohibited.

If you are not the intended recipient, please contact the sender and delete all copies.
Next in thread → Next in month →