← Prev in month ← Prev in thread

Re: [security-services] Status of and recommendation on SAML versioninfo

From
RL 'Bob' Morgan <>
Date
2002-02-06T16:40:42+00:00
ID
Thread
Re: [security-services] Status of and recommendation on SAML versioninfo
On Tue, 5 Feb 2002, Eve L. Maler wrote:

> I had been advocating that the namespace URI (a) not be a "real" web
> resource/filename, and (b) not contain version information.  However,
> common practice has overtaken me on both counts:

I had also advocated, in my message:

  Date: Tue, 29 Jan 2002 00:58:59 -0800 (PST)
  From: RL 'Bob' Morgan <>
  To: OASIS Security Services TC <>
  Cc: Karl Best <>
  Subject: [security-services] URNs for SAML spec identifiers

  http://lists.oasis-open.org/archives/security-services/200201/msg00225.html

that we use URNs for namespace identifiers, as does DSMLv2.

> - Regarding real filenames: Schema tools are happiest when they can
> use the namespace name as the filename for accessing the schema.
> This isn't supposed to be required behavior, but it might as well be
> given the state of the tools.

By "use the namespace name as the filename" do you mean just the part of
the name after the last slash?  Or do you mean that tools expect namespace
names to be real URLs via which schema documents can be fetched?

> Thus, using these two rationales, I propose that we use something like the
> following as namespace URIs for our two namespaces:
>
>    http://www.oasis-open.org/committees/security/saml/1.0/saml-assertion.xsd
>    http://www.oasis-open.org/committees/security/saml/1.0/saml-protocol.xsd

If we used URNs as I proposed earlier, these namespaces might be called:

  urn:oasis:names:tc:SAML:1.0:saml-assertion.xsd
  urn:oasis:names:tc:SAML:1.0:saml-protocol.xsd

Would that work given the contraints you mention, or not?

 - RL "Bob"
← Prev in month ← Prev in thread