← Prev in month ← Prev in thread

issue: description of SubjectConfirmation/KeyInfo (in SAML core)precludes impersonation

From
Ron Monzillo <>
Date
2004-02-05T18:29:33+00:00
ID
Thread
issue: description of SubjectConfirmation/KeyInfo (in SAML core)precludes impersonation
676: <ds:KeyInfo> [Optional]
676: An XML Signature [XMLSig] element that provides access to a 
cryptographic key held by the subject.

The wss stp attempts to describe a holer-of-key impersonation model, 
where the
entity that confirms knowledge of the key is other than the subject of 
the assertion.

IMO, the text in SAML core, should be changed to say something like:

676: An XML Signature [XMLSig] element that identifies a cryptographic 
key that must be demonstrated to satisfy the confirmation method.
← Prev in month ← Prev in thread