Next in thread →
Next in month →
RE: [ws-sx] Issue PR013: Need EncryptedSupportingTokens assertion
In today's call during the discussion of PR013 we were discussing encrypting a password of a username token (or the whole token) without the need for a signature. Couldn't the policy look something like this: AsymmetricBindingAssertion Initiator token: UsernameToken Recipient token: X509Token No timestamp EncryptedParts UsernameToken Wouldn't this work? It wouldn't require a signature would it?
Next in thread →
Next in month →