Re: [security-services] SAML Profiles for X.509 Subjects

From
Tom Scavo <>
Date
2006-08-29T21:22:41+00:00
ID
Thread
Re: [security-services] SAML Profiles for X.509 Subjects
I don't claim to understand proper procedure with respect to the
public review process, so if I'm way off base here, someone please
correct me.

On 8/29/06, Ari Kermaier <> wrote:
> What is the impact of these new documents on the CD/public review cycle of the sstc-saml-x509-authn-attrib-profile document? I mean, do you intend them to obsolete/replace the existing profile spec, or for them to exist separately?

Well, I guess that's for the SSTC to decide.  Rather than fork a new
document stream that competes with the current one, I'd prefer we
consider draft-11 in lieu of its predecessors, of course.  If the
Committee would rather not do that, then I'd change the name to
draft-01 and go from there.

CD-02 is not usable by our project (and we're not alone in this
regard).  For one thing, we need a separate SAML Assertion Profile for
X.509 Subjects so that we can write binding profiles that will be
submitted elsewhere (probably GGF).

We will circulate these documents at a series of workshops scheduled at GGF18:

http://www.ggf.org/gf/event_schedule/index.php?id=358
http://www.ggf.org/gf/event_schedule/index.php?id=454
http://www.ggf.org/gf/event_schedule/index.php?id=455
http://www.ggf.org/gf/event_schedule/index.php?id=456

An important goal of this workshop is an interop testbed for grid
projects implementing attribute-based access control.  We hope these
documents provide a foundation (or at least a basis for discussion)
for this testbed.

Tom Scavo
NCSA/University of Illinois