Re: [security-services] NIST prohibits use of SAML assertions atLOA 4

From
=JeffH <>
Date
2008-06-27T23:55:45+00:00
ID
Thread
Re: [security-services] NIST prohibits use of SAML assertions atLOA 4
Paul Madsen wrote:
 > more generally, rather than pick on SAML, the policy should preclude
 > 'browser redirect SSO systems that rely on bearer tokens'

doh!  but of course..

=JeffH