> is there a statement from this TC regarding the usage of
> OASIS WSS to provide message-level security for the SAML SOAP
> Binding? Is it up to the implementers to use WSS if they find
> its necessary - I'm asking because from my point of view the
> usage of WSS sould be mentioned in the SAML Bindings Spec if
> it was so?!
Why? There are a million ways to authenticate a SOAP message, it doesn't
seem realistic to name them all. There is already language that says SOAP
headers may be present to assist in message routing or security. I think
that covers WSS pretty directly...
-- Scott