← Prev in month ← Prev in thread
Next in thread → Next in month →

Potential error in AuthContext spec?

From
Philpott, Robert <>
Date
2013-06-12T17:46:42+00:00
ID
Thread
Potential error in AuthContext spec?
WOW… it’s been a long time since I felt comfortable down in the bowels of the
AuthnContext spec (oh wait… I never felt comfortable there

J).

 

We have a use case where someone is attempting to create 
aninstance document  for the class 
TimeSynchToken and it appears there is an error in the spec.

 

The TimeSyncToken schema defines the
AuthnMethodBaseType to be a restriction of 
AuthnMethodBaseType where PrincipalAuthenticationMethod is optional and Authenticator is required.

 

However, the Token element is in the PrincipalAuthenticationMechanismType, not in the
AuthenticatorSequenceGroup and thus it can’t be part of the Authenticator element.

 

So we’re stumped as to how to create a 
TimeSyncToken authenticator. 

 

Are we missing something?

 

Rob Philpott
| Senior Technologist | RSA, the Security Division of EMC

eMail:
 | Office: 781.515.7115 | Mobile: 617.510.0893
← Prev in month ← Prev in thread
Next in thread → Next in month →