Next in thread → Next in month →

Re: [security-services] SSO validity period

From
Conor P. Cahill <>
Date
2004-04-06T15:36:06+00:00
ID
Thread
Re: [security-services] SSO validity period
RL 'Bob' Morgan wrote on 4/6/2004, 11:21 AM:

 >
 > I'm not sure which "this window" you're referring to, but I think that
 > even if stolen bearer token issues go away in the scenario you
 > describe, there is still a need for a generic validity period
 > (as described in my other note, the "throw-away-after" date) in
 > this case.

That was the time period that I was referring to in "this window".  I
agree that we need to support such a window, but I do not think it
should be mandatory to have it specified.

Conor
Next in thread → Next in month →