[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [xri] Minutes: XRI TC Telecon 2-3PM PT Thursday 2009-07-16
|
Scott Cantor wrote: I suppose it is required for key rotation purposes.Markus Sabadello wrote on 2009-07-20: Looks like being able to specify signing key, authentication key, encryption key separately is the fave of some of the security experts. If we take that position, then we would need something like saml:KeyDescriptor. Perhaps we can just borrow the text or reference it.delineate specific keys for the purposes of signing (incl. TLS) and encryption, and to add some fairly non-well-thought-out bits for encryption algorithm support. The delta here may be less, the same, or more. I'm not really equipped to answer that. Something SAML should have done but didn't is make the KeyDescriptor wrapper more extensible. Having something to use later and just leave relatively empty for now is probably the best compromise. -- Scott --------------------------------------------------------------------- To unsubscribe from this mail list, you must leave the OASIS TC that generates this mail. Follow this link to all your TCs in OASIS at: https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php |
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]