Re: [security-services] Trust in artifact resolution
> (I want to avoid authenticating the SAML requester to the SAML > responder, and vice versa; but it's fine for the thing-in-the-middle > to authenticate itself to both parties). Just to note that this is almost inverse to the HTTP user agent use- case, which I guess is why I'm having this problem. josh.