← Prev in month ← Prev in thread

Re: [security-services] Minutes from SSTC Call (Tuesday 22 November 2016) ---- RE: Proposed Agenda for SSTC Telecon (Tuesday 22 November 2016)

From
Madalina Sultan <>
Date
2016-12-02T09:46:56+00:00
ID
Thread
Re: [security-services] Minutes from SSTC Call (Tuesday 22 November 2016) ---- RE: Proposed Agenda for SSTC Telecon (Tuesday 22 November 2016)
Hi all,

I have made some changes to the document based on your input and added the Conformance section: https://www.oasis-open.org/apps/org/workgroup/security/download.php/59498

Regarding the metadata flag that announces support, the document currently states that it is optional. So it doesn't enforce anything. Do you think it will be more clear if I start from a specification like: "If an Identity Provider supports this extension, then it MUST define the metadata flag" ?

Regards,

Madalina

On Fri, Nov 25, 2016 at 6:23 PM, Cantor, Scott <> wrote:
On 11/23/16, 4:39 PM, "Rainer Hoerbe" <> wrote:

> I am not referring to the overhead in writing the spec, but for the user to understand and follow it.

I don't think this adds any meaningful complexity.

> In general it is better not to include stuff that is not used, reducing the burden on the reader. As said, if people

> thing they would like to announce capabilities in metadata, then the text should provide processing clues.

The common processing across all of metadata is that you look at it and base decisions on it. I don't know what we would need to say here beyond "if you don't see the attribute, don't send the extension", but that could certainly be said.

-- Scott

This message may contain information that is not intended for you. If you are not the addressee or if this message was sent to you by mistake, you are requested to inform the sender and delete the message. Connectis accepts no liability for damage of any kind resulting from the risks inherent in the electronic transmission of messages.
← Prev in month ← Prev in thread