RE: [saml-dev] SAML2HoKAP question

From
Scott Cantor <>
Date
2009-05-20T00:44:23+00:00
ID
062301c9d8e4$1b6dbed0$52493c70$@
Thread
RE: [saml-dev] SAML2HoKAP question
Josh Howlett wrote on 2009-05-19:
>  Ok. So I assume that the NameID is used by the SAML issuer to name an
> intermediate delegate who can wield the assertion as an attesting entity?

Yes, but this is just informational. You don't have to do anything special
to indirectly authenticate the delegate. It's there in case you don't want
to allow delegation (which the condition does a much better job of ensuring,
not to mention supporting a chain of delegates).

-- Scott