I would like to add to the list SP/IdP Session Sync (as discussed in Kantara eGov WG with the SP doing IsPassive requests to refresh the user's IdP session).
Regarding the use of HTML5: An improved privacy profile with reduced linkability would be a hot feature in Europe, saving the world from having to rush into uProve-like solutions. I posted a draft at http://identityblog.portalverbund.at/en/node/37.
- Rainer
Am 29.05.2012 um 17:01 schrieb Cantor, Scott:
>>
>> (e) SAML 2.0.1 and Security Considerations doc
>> - Status: SSTC agrees to proceed on this in 2012.
>> - Issues: Should metadata and trust exchange frameworks
>> be made mandatory.
>> - Status: Scott has emailed a proposal to the list.
>> - AI: Scott to start a "SAML2.x Planning Wiki Page" with
>> list of items and/or changes to go into SAML2.x
>
> Finally started this:
>
> http://wiki.oasis-open.org/security/SAML2Revision
>
> I'll be making additional updates before the call. I would suggest one of
> our immediate goals would be to formally agree to the things I think we
> already have agreed to, and maybe try and move some of the "close to
> consensus" points to that category.
>
> -- Scott
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail:
> For additional commands, e-mail:
>