In section 3.5 'PE5: Rules for NameIDPolicy' the two options for
additional wording refer to the 'persistent' format where they should
refer to the 'transient' format. I think Scott just had a typo in the
wording he proposed which he subsequently corrected but it looks like
the correction didn't make it into this doc.
---
1. Strict option:
"Finally, note that since the
urn:oasis:names:tc:SAML:2.0:nameid-format:persistent Format value
(see Section 8.3.8) implicitly results in a new identifier being created
during the handling of most
requests, the AllowCreate attribute MUST be set to true in order for
such a value to be returned."
2. Optimized option:
"Finally, note that since them
urn:oasis:names:tc:SAML:2.0:nameid-format:persistent Format
value (see Section 8.3.8) implicitly results in a new identifier being
created during the handling of
most requests, the AllowCreate attribute MUST be ignored by the identity
provider when such an
identifier is requested or issued."
> -----Original Message-----
> From: [mailto:]
> Sent: Monday, April 11, 2005 7:08 PM
> To:
> Subject: [security-services] Groups - Errata for the OASIS Security
> Assertion Markup Language (SAML) V2.0; Working Draft 04
(sstc-saml-errata-
> 2.0-draft-04.pdf) uploaded
>
> The document named Errata for the OASIS Security Assertion Markup
Language
> (SAML) V2.0; Working Draft 04 (sstc-saml-errata-2.0-draft-04.pdf) has
been
> submitted by Jahan Moreh to the OASIS Security Services (SAML) TC
document
> repository.
>
> Document Description:
> This document lists the reported errata and potential errata against
the
> OASIS SAML 2.0 Committee Specifications and their status. This draft
(04)
> has proposed text for all PEs except PE 10. A word version is also
> available.
>
> View Document Details:
> http://www.oasis-
> open.org/apps/org/workgroup/security/document.php?document_id=12210
>
> Download Document:
> http://www.oasis-
>
open.org/apps/org/workgroup/security/download.php/12210/sstc-saml-errata
-
> 2.0-draft-04.pdf
>
>
> PLEASE NOTE: If the above links do not work for you, your email
> application
> may be breaking the link into two pieces. You may be able to copy and
> paste
> the entire link address into the address field of your web browser.
>
> -OASIS Open Administration