RE: [security-services] RE: AuthenticationMethod / NameIdentifier and Kerberos authentication

From
Tim Alsop <>
Date
2004-04-14T16:41:59+00:00
ID
Thread
RE: [security-services] RE: AuthenticationMethod / NameIdentifier and Kerberos authentication
Title: RE: [security-services] RE: AuthenticationMethod / NameIdentifier and Kerberos authentication

Yes, I think the sense is that we're going to be able to dump Method and

move it into a set of context class URIs, that would keep the URIs the same,

if we want. Or if we change them, then it's moot, I guess. And context

classes are not the best way to capture preauth, given the potential

variability, so using actual AuthnContext statements and making sure the

SAML schema for that can capture this information is the real work item.

Tim> So, can I assume that AuthnContext has been, or will be specified to support Kerberos pre-auth ? I guess I am just making sure that this work item is currently owned by somebody ?

Cheers, Tim.