← Prev in month ← Prev in thread
Next in thread → Next in month →

RE: [security-services] Authentication Response IssuerName vs. As sertionIssuerName

From
Conor P. Cahill <>
Date
2005-06-10T15:38:07+00:00
ID
Thread
RE: [security-services] Authentication Response IssuerName vs. As sertionIssuerName
Thomas Wisniewski wrote on 6/10/2005, 10:16 AM:

  
Conor, what do you
do in the case where the Response is not signed but someone is sending
you an EncryptedAssertion?
  

  
  
How do you know who
the issuer is (particularly if it's an unsolicited Response)?

I was adding onto
Scott's point (so Scott said a MUST for encrypting and I said it
probably should *also* be a MUST for signing.

I guess I could have clarified my concern to say "when the response
isn't signed and the assertion is not encrypted".

Conor
← Prev in month ← Prev in thread
Next in thread → Next in month →