← Prev in month
← Prev in thread
Next in thread →
Next in month →
Re: [saml-dev] SAML V2.0 Holder-of-Key Web Browser SSO Profile notimmune against man-in-the-middle attack
[cc'ing the SAML Public Comment list since the Holder-of-Key Web Browser SSO Profile is under Public Review at this time] Hi Marc, Thanks for the note, and sorry for not replying sooner. Yes, you bring up a good point. Either the statements involving the "man-in-the-middle" need to be removed or additional requirements need to be added that make the statements true. I've been discussing this with the spec's primary author, Nate Klingenstein, offline (as you know). Your suggestion to use a known key seems reasonable. Again, thanks for the feedback. Tom On Thu, Apr 16, 2009 at 8:52 AM, Marc Stern <> wrote:
← Prev in month
← Prev in thread
Next in thread →
Next in month →