RE: [wss] Comments on Sender-Vouches-Signed section in SAML Interop draft

From
Levinson, Richard <>
Date
2004-03-25T13:37:29+00:00
ID
BB183C583D38084A8B78F7D01242460409B65A62@maex04
Thread
RE: [wss] Comments on Sender-Vouches-Signed section in SAML Interop draft
Thanks Maneesh,

 

I am keeping track of the updates and will submit a new 
version in a couple

of weeks in time before the SAML Interop is scheduled. In 
the meantime,

please keep notifying me of additional changes that need to 
be addressed.

 

    Thanks,

 

    Rich

  

  
  From: Maneesh Sahu 
  [mailto:] 
Sent: Wednesday, March 24, 2004 
  6:38 PM
To: Levinson, Richard; 
  
Subject: RE: [wss] Comments on 
  Sender-Vouches-Signed section in SAML Interop draft

  

  

  
Rich,

  
 

  
Another update 
  required in the “WSS:SAML Token Profile” and the “WSS: SAML Interop 1 
  Scenarios” documents is the algorithm name for the STR-Transform that goes 
  into the dsig:Transform Algorithm attribute value.  The SAML documents 
  list the algorithm as http://schemas.xmlsoap.org/ws/2003/06/STR-Transform 
  in the examples.

  
 

  
The WSS Soap Message 
  Security document however recommends: http://www.docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd#STR-Transform 
  

  
 

  
--ms

  
 

  

  

  
  

  
From: 
  Levinson, Richard [mailto:] 
Sent: Tuesday, March 23, 2004 10:46 
  AM
To: Maneesh Sahu; 
  
Subject: RE: [wss] Comments on 
  Sender-Vouches-Signed section in SAML Interop 
  draft

  
 

  
Maneesh,

  
 

  
Thank you for calling 
  my attention to your earlier email at today's meeting. 
  

  
I had missed it 
  earlier.

  
 

  
In any event, you are 
  correct on all 3 comments. The first (rsa-sha1) 
  and

  
third (#attesterCert) 
  are simply typos that should be corrected.

  
 

  
The 2nd comment 
  (STR-Transform) is redundant as you indicate, 
  

  
however, it was 
  derived from the SAML profile document, 

  
which used the STR to 
  reference an external assertion. 

  
Also, it is intended 
  to be demonstrative of using the

  
STR to reference 
  assertions, and its redundancy should not

  
interfere with 
  operation: i.e. a message should not be rejected,

  
in general, as long 
  as it is compliant with the WS-Security spec,

  
and associated token 
  profile.

  
 

  
I will hold off 
  updating the spec with the typo fixes for a 
couple

  
of weeks to see if 
  additional comments come in.

  

  
 

  

  
    
  Thanks,

  

  
 

  

  
    
  Rich Levinson

  

  
 

  

  
 

  
 

  
    

    
    

    
From: 
    Maneesh Sahu [mailto:] 
Sent: Thursday, February 05, 2004 8:09 
    PM
To: 
    
Subject: [wss] Comments on 
    Sender-Vouches-Signed section in SAML Interop 
    draft

    

    

    
Hi,

    

    
 

    

    
I have a few comments and need 
    some clarifications on the example provided with the sender-vouches:signed 
    section:

    

    
 

    

    
Page 
    25

    

    
 

    

    
Line 688: Shouldnt the signature 
    method be rsa-sha1 instead of hmac-sha1 ?

    

    
Line 691: For sender-vouches, 
    the STR-Transform may be a bit redundant. It may be useful for holder-of-key 
    where the assertions are immutable and need to be referenced differently. 
    

    

    
Line 708: Shouldnt the reference 
    URI be #attesterCert instead of attesterCert 
    ?

    

    
 

    

    
Apologies if these issues have 
    been tackled earlier...this is my first day on the 
    group.

    

    
 

    

    
--ms

    

    
Maneesh 
    Sahu

    

    
Westbridge Technology, 
    Inc.