I am not sure what your point here is. Are you suggesting that SAML
bearer tokens arent "useful"?
That seems a strange thought to me: for example, you are co-author of a
draft which uses SAML bearer tokens to accomplish SSO.
http://www.ibm.com/developerworks/library/ws-fedpass/
Both the SAML 1.1 and SAML 2.0 web browser POST profiles are based on
use of a SAML bearer token. You can find more information about
these standards at:
http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security
Any of these protocols could be used following the completion of
Scenario #2.
- prateek
> While the specifications are extensible and there are a lot of various
> scenarios, it would be more beneficial to have scenarios that are
> useful. I find scenario #2 not very useful as I'm not seeing the
> completion of the scenario, the token returned (a SAML bearer token)
> never gets used. Not finding a real use for this scenario.
>
> Anthony Nadalin | Work 512.838.0085 | Cell 512.289.4122
>