← Prev in month ← Prev in thread
Next in thread → Next in month →

RE: [security-services] FW: Attribute Authority info in Authentication Assertion proposal (f2f #5 action item)

From
Simon Godik <>
Date
2001-12-18T23:41:45+00:00
ID
Thread
RE: [security-services] FW: Attribute Authority info in Authentication Assertion proposal (f2f #5 action item)
Title: RE: [security-services] FW: Attribute Authority info in Authentication Assertion proposal	(f2f #5 action item)

I agree with Scott, that 'any' semantics is simplier.

Simon

-----Original Message-----

From: Scott Cantor [mailto:]

Sent: Tuesday, December 18, 2001 11:01 AM

To: 'Simon Godik'; 

Subject: RE: [security-services] FW: Attribute Authority info in

Authentication Assertion proposal (f2f #5 action item)

>All authorities pointed to by the AuthorityBinding list must be queried

by

>the relying party. 

FWIW, Shibboleth is currently defining simpler semantics of equivalence

that tell the relying party to query any of them rather than all of

them. This sidesteps more complex questions about conflicting attribute

responses.

For myself, I favor Simon's proposal, modified in this fashion, as a

starting point toward a more dynamically interoperable model. I

understand the provisioning argument, but I don't see why passing

information dynamically isn't preferable to not, even if it doesn't get

you all the way there. This doesn't seem like a kitchen sink thing to

me.

We can use Advice, I just don't think it's as good a solution.

-- Scott
← Prev in month ← Prev in thread
Next in thread → Next in month →