RE: Authentication Context Comments

From
Paul Madsen <>
Date
2004-11-16T18:05:24+00:00
ID
Thread
RE: Authentication Context Comments
Hi 
Prateek, I agree with your proposed change (as long as the 'AuthNMethod' was a 
typo and you meant AuthnMethod :-) )

 

Thanks

 

Paul

  
-----Original Message-----
From: Mishra, Prateek 
  [mailto:]
Sent: Tuesday, November 16, 2004 
  11:46 AM
To: 
Cc: 
  ; 
Subject: Authentication 
  Context Comments 

  

  
I had taken an 
  editorial action to review recent comments on the authentication context 
  specification and check if all updates had been picked up in schema and 
  documents. The only comment from the relevant time period I found 
  was:

  
 

  
Errors in 
  Authentication Context Schemas

  
 

  
http://lists.oasis-open.org/archives/security-services/200409/msg00089.html

  
 

  
Resolutions to 
  date:

  
 

  
1) No change, the 
  idea is that RestrictedLengthType is a utility type 
  used by RestrictedPassword.

  
The minimum size 
  restriction is intentional rather than 
accidental.

  
 

  
2) Proposed change 
  has been made.

  
 

  
3) Use of <AuthenticationMethod> in the core AC schema versus 
  <AuthNMethod> in all 
  derived

  
classes. The intention here 
  is to use the same name (the derived classes all 

  
restrict AuthenticationMethod but refer to AuthNMethod instead). This change has not been 
  made.

  
 

  
 

  
Proposed change: 
    replace AuthenticationMethod by AuthNMethod in core AC schema

  
(and 
specification).