← Prev in month ← Prev in thread
Next in thread → Next in month →

Re: [security-services] Groups - sstc-saml-holder-of-key-browser-sso-draft-08.pdf (sstc-saml-holder-of-key-browser-sso-draft-09.pdf) uploaded

From
Tom Scavo <>
Date
2008-11-12T01:46:07+00:00
ID
Thread
Re: [security-services] Groups - sstc-saml-holder-of-key-browser-sso-draft-08.pdf (sstc-saml-holder-of-key-browser-sso-draft-09.pdf) uploaded
On Tue, Nov 11, 2008 at 8:27 PM, Nate Klingenstein <> wrote:
> Also note that the some of the requirements in 2.5.3 might be merged.  For
> example, rather than the split text on 425-427 and 431-435, we might just
> require that every assertion returned in the response be holder-of-key.

I don't think there's any doubt about that.  If a <saml:Subject> is
included in the request, "strongly matches" pretty much guarantees
every assertion is HoK.  If there is no <saml:Subject> in the request,
we've chosen to interpret that as HoK subject confirmation using
<ds:X509Certificate>, so "strongly matches" still applies
(implicitly).

Tom
← Prev in month ← Prev in thread
Next in thread → Next in month →