Next in thread → Next in month →

FW: [provision] DU0002 RA - PSP Create Accounts

From
Tony Gullotta <>
Date
2002-04-15T17:42:17+00:00
ID
Thread
FW: [provision] DU0002 RA - PSP Create Accounts
One 
last thing. I don't think we should address organization information enabling a 
more diverse nature of organizing identities per implementation without creating 
dependencies within the protocol. So, if organization information is needed, it 
would be part of the identity schema.

 

Tony

 

-----Original Message-----
From: Tony Gullotta 
Sent: 
Monday, April 15, 2002 10:40 AM
To: 'Darran Rolls'; 

Subject: RE: [provision] DU0002 RA - 
PSP Create Accounts

I 
concur with Darran with one change and one addition.

 

1. I 
don't believe step "e" below is needd unless we're implying the PSP is going to 
resend the status to the RA if the RA does not acknowledge the previous message 
within a time threshold.

 

2. It 
appears as though this use case has implied prior trust being established 
between the RA and the PSP. Is this sufficient for this first phase, or should 
we address a less trusting model? I'm thinking about something that requires 
some sort of certificate of authenticity is needed to ensure the identity 
information being passed is accurate. This could be the RA's certification if 
trust has been pre-established, or a third party if not. This would most likely 
be something that SAML could help out with.

 

Tony

  
-----Original Message-----
From: Darran Rolls 
  [mailto:]
Sent: Tuesday, April 02, 2002 4:53 
  AM
To: 
Subject: RE: 
  [provision] DU0002 RA - PSP Create Accounts

  

  
I have the 
  following comments on DU0002:

  
 

  
1.     
  My interpretation 
  of this UC is that it describes the request for the creation of a new vID. 
   Based on this assumption, is the organization simply one of the 
  attributes required to create a new vID?  If so maybe we should make the 
  description explain this

  
2.     
  On l-56, I don’t 
  understand why the connection information is needed?

  
3.     
  On l-69, I think 
  we should not use the word bind 

  
4.     
  Based on 1 
  (above), shouldn’t step on l-69 through 76 simply read:

  
a.     
  RA sends “create 
  vID” request to PSP specifying the required vID and required vID 
  attributes

  
b.     
  PSP responds with 
  RequestID

  
c.     
  PSP creates new 
  vID

  
d.     
  PSP sends status 
  message to RA of operation success or failure

  
e.     
  RA sends message 
  receipt to PSP

  
5.     
  We may want to 
  annotate outside the steps that a PSP may choose to implement the creation of 
  downstream PST entries based on the information in receives for the vID (as 
  you imply in the steps) – this being a simple implementation of a PSP-PST 
  create request

  
6.     
  Post conditions on 
  l-78 should read “A vID has been added to the PSP 

  
 

  
 

  
 

  

  
Darran 
  Rolls  
MSIM  
   
AIM    drollswaveset 
  
YIM    drolls_waveset
http://www.waveset.com/ 
  
 
  

  
 

  
-----Original 
  Message-----
From: 
  Darran Rolls 
  
Sent: Monday, March 25, 2002 
  11:25 PM
To: 
  
Subject: [provision] DU0002 RA - PSP 
  Create Accounts

  
 

  
http://lists.oasis-open.org/archives/provision/200203/msg00009.html

  
 

  
Darran 
  Rolls  
MSIM  
   
AIM    drollswaveset 
  
YIM    drolls_waveset
http://www.waveset.com/ 
  
Next in thread → Next in month →