Re: [saml-dev] Digital Signature Usage in X.509 Subject Attribute Query Specifications

From
Anil John <>
Date
2009-04-08T18:16:26+00:00
ID
Thread
Re: [saml-dev] Digital Signature Usage in X.509 Subject Attribute Query Specifications
On Wed, Apr 8, 2009 at 11:49 AM, Scott Cantor <> wrote:
> The main case that comes up is relying on WS-Security for actual
> authentication of the SAML messages themselves, typically the request, and
> in that case you wouldn't *also* sign the SAML request itself, typically.

Understood.

Any insights to share regarding the MUST vs. MAY usage of signing of
the parts of the response in the two specs?

Regards,

- Anil