Re: [security-services] NIST prohibits use of SAML assertions atLOA 4
Paul Madsen wrote: > more generally, rather than pick on SAML, the policy should preclude > 'browser redirect SSO systems that rely on bearer tokens' doh! but of course.. =JeffH
Paul Madsen wrote: > more generally, rather than pick on SAML, the policy should preclude > 'browser redirect SSO systems that rely on bearer tokens' doh! but of course.. =JeffH