RE: [security-services] Article: Debunking SAML myths and misunderstandings

From
Charles Knouse <>
Date
2003-07-23T17:39:03+00:00
ID
Thread
RE: [security-services] Article: Debunking SAML myths and misunderstandings
I can provide some context for this
article. The author, Frank Cohen, was the moderator for a talk
on SAML that I gave in February at the Web Services SIG of the Software Development
Forum. Frank developed his paper from the talk and his recollection of the
discussion. Some of the seemingly odd topics can be traced to questions that
came up, for example, the topic “Misunderstanding: Canonicalization
in XML Signatures is not needed.” came from my attempts to convince a
skeptical member of the audience that canonicalization was indeed needed for
XML Signatures. 

 

Frank sent me a draft of the paper for
review and I gave him a number of comments and corrections. I did not see the
final draft before it was published. In looking over the final paper I see he
took some of my corrections but not others. 

 

-- Charles

 

-----Original Message-----

From: Philpott, Robert
[mailto:] 

Sent: Tuesday, July 22, 2003 10:14
AM

To:
''

Subject: [security-services]
Article: Debunking SAML myths and misunderstandings 

 

The article mentioned on the call...

 

http://www-106.ibm.com/developerworks/xml/library/x-samlmyth.html

 

Rob Philpott 

RSA Security Inc. 

The Most Trusted Name in e-Security 

Tel: 781-515-7115 

Mobile: 617-510-0893 

Fax: 781-515-7020 

mailto: