RE: [security-services] X509 Authn Attribute Profile erratum?

From
Philpott, Robert <>
Date
2006-04-11T16:16:53+00:00
ID
Thread
RE: [security-services] X509 Authn Attribute Profile erratum?
I believe the intro is wrong and that
section 4.2.1 is correct.  I recommend changing the phrase:

 

“both by signing the <Response>
message and through TLS or SSL server authentication.”

 

To

 

“both by signing the <Assertion>
element in the <Response> message and sending the <Response> using TLS
or SSL server authentication.”

 

Rob Philpott

Senior Consulting Engineer

RSA Security Inc.

Tel: 781-515-7115

Mobile:
617-510-0893

Fax: 781-515-7020

Email: 

I-name:  =Rob.Philpott

From: Ari Kermaier
[mailto:] 

Sent: Tuesday, April 04, 2006
11:36 AM

To: 

Subject: [security-services] X509
Authn Attribute Profile erratum?

 

In the overview in Section 4
"Encrypted/Signed Mode" line 194, the profile specifies that the
responding IdP MUST sign the <Response>.

 

In Section 4.2.1 "<Response> Usage" line 250
and in Section 4.2.3 "Use of Digital Signatures" line 280 it
specifies that the <Assertion> MUST be signed.

 

Which is it?

 

Ari Kermaier