Next in thread → Next in month →

RE: [security-services] List of possible implementation features forSAML 2.0

From
Scott Cantor <>
Date
2004-07-01T15:01:30+00:00
ID
Thread
RE: [security-services] List of possible implementation features forSAML 2.0
> In fact, here is a different position altogether: remove the GET part
> completely and retain only the POST delivery method. This limits the
> implementations to just one form and avoids the "referrer" issue.

I think we'd get push back (in fact I know we would), since one of the
primary advantages of artifact is the use of a redirect without requiring
JavaScript to automate the delivery.

It simply bears noting that it's a bit less secure, though also mitigated by
other additions, like the replay detection at SP.

-- Scott
Next in thread → Next in month →