Re: [security-services] Untrusted Service Provider Profile

From
Tom Scavo <>
Date
2007-03-01T00:48:28+00:00
ID
Thread
Re: [security-services] Untrusted Service Provider Profile
The OpenID model is thought to be flawed, as shown in this blog entry:

http://www.identityblog.com/?p=659

So I guess it depends on how you propose to do IdP Discovery.  How
does the untrusted SP know the principal's preferred IdP?

Tom

On 2/28/07, Cameron Morris <> wrote:
> I'd love to see a SAML model where an SP can trust an IDP, but an IDP doesn't necessarily trust an SP.  This is much more like the OpenID model.  But there is no reason SAML cannot do this.
>
> Here is how I'd see it:
> 1. An unknown/untrusted SP sends a signed authentication request to a trusted IDP.
> 2. The IDP looks up the metadata of the SP (it must be available online and on a secure endpoint such as https).
> 3. The IDP verifies that the metadata and the request come from the same provider.
> 4. The IDP sends the assertion.
>
> This certainly can be done within existing spec, but it mandates several things that are optional in the spec.  Should this be formalized as a profile?  Are people interested in such a profile?
>
> - Cameron Morris
>
>
>
>