Re: [security-services] SAML2 Holder-of-Key Assertion Profile

From
Tom Scavo <>
Date
2008-08-18T00:27:19+00:00
ID
Thread
Re: [security-services] SAML2 Holder-of-Key Assertion Profile
On Sun, Aug 17, 2008 at 7:06 PM, Cahill, Conor P
<> wrote:
>
> ... the normal interpretation for SubjectConfirmation is that
> the proof (for holder of key) is done at the time of the presentation of
> the assertion, not some days or months ago.

Okay, that's fine.

> So, my $.02 is that you don't need ProofInstant.

Under the assumption you stated above, I agree, yes.

Thanks, Conor.

Tom