RE: [security-services] Rob's errata: Conf 2a

From
Thomas Wisniewski <>
Date
2005-09-13T16:05:23+00:00
ID
Thread
RE: [security-services] Rob's errata: Conf 2a
Title: RE: [security-services] Rob's errata: Conf 2a

Scott, where does the text suggest that both methods are required for 'transmitting' SAMLart? 

Tom.

> -----Original Message-----

> From: Scott Cantor [mailto:] 

> Sent: Tuesday, September 13, 2005 12:02 PM

> To: 'Brian Campbell'; 'Robert Philpott (RSA)'; 'SAML'

> Subject: RE: [security-services] Rob's errata: Conf 2a

> 

> 

> > So, to be conformant, is an implementation required to send/produce

> > artifacts via both POST and GET?  Or just to accept them via either

> > method? 

> 

> Both. The binding is not specific to POST or GET, it requires 

> both as a

> method to transmit or receive an artifact. This was copied from ID-FF,

> although nobody seemed to know that it was there. The purpose 

> is to allow

> GET vs. POST to be decided as a deployment issue independent of the

> deployment decision of whether to use artifact or not. The only reason

> Redirect and POST are separate bindings is that they're such different

> encodings.

> 

> -- Scott

> 

> 

> ---------------------------------------------------------------------

> To unsubscribe from this mail list, you must leave the OASIS TC that

> generates this mail.  You may a link to this group and all 

> your TCs in OASIS

> at:

> https://www.oasis-open.org/apps/org/workgroup/portal/my_workgr

> oups.php 

>