Next in thread →
Next in month →
Re: Note on Digital Signing in SAML
Agreed. Often, both signatures are required to establish the authenticity of the assertion. Kelvin Beeck wrote: <snip/> > > It seems to me that assertions would often need to be signed independent of > a composite signature (as part of the protocol binding) because issued > assertions usually become the input for other queries (eg. an authentication > assertion as input to an PDP authorization query) or may be bound to a > payload. > > The requirement is based on the trust relationship - i.e. do I trust an > assertion because I trust the bearer, or do I need to verify that the > assertion came from the stated issuer (I would think so).
Next in thread →
Next in month →