RE: [wss] SAML Token Brainstorming

From
Mishra, Prateek <>
Date
2003-10-08T08:28:46+00:00
ID
BB183C583D38084A8B78F7D0124246040448CFC4@maex04
Thread
RE: [wss] SAML Token Brainstorming
As discussed on the call, we should discuss how encryption should be
integrated with the SAML token profile. I agree that a key in or referenced
from a (holder-of-key) assertion could be used in the same manner that a
key in an x509 cert was used in our encryption scenarios.

<Prateek>
Regrettably, I missed this discussion but here is my guess: the key found in
the holder-of-key assertion is used to encrypt a (generated) symmetric key,
which in turn is used to encrypt the body. Can you confirm that this is the
case of interest?
</Prateek>