← Prev in month ← Prev in thread
Next in thread → Next in month →

SAML Profile draft

From
Anne Anderson <>
Date
2003-03-20T14:03:44+00:00
ID
Thread
SAML Profile draft
Attached are three files representing a proposal for
incorporating the XACML Request and Response formats into SAML
2.0:
  - Changes to the SAML 1.0 Specification
  - Changes to the SAML 1.0 Assertion Schema
  - Changes to the SAML 1.0 Protocol Schema

In order to retain backwards compatibility, the SAML 1.0
AuthorizationDecisionQuery and AuthorizationDecisionStatement are
retained.  There are known users of these formats.

An overview of this proposal follows.

SAML 2.0 AuthorizationDecisionQuery contains:

1. XACML input context (xacml-context:Request)
2. flag (InputContextOnly) indicating whether
   a) only the content of the context from the PEP can be used
      ("what if" mode), or
   b) the PDP can use attribute values obtained from other
      sources
3. flag (ReturnContext) indicating whether returned assertion
   should contain input context that decision was based on.

The response to the AuthorizationDecisionQuery is returned in the
existing SAML Response, but uses a new
AuthorizationDecisionStatement containing

1. XACML output context (xacml-context:Response)
2. (optional) XACML input context used. (xacml-context:Request)

The input context is optional in the sense that it would not
normally be provided, but if the ReturnContext flag was set in
the request, the PDP must provide it.

Note that there is already a SAML attribute (InResponseTo) for
passing the RequestId back in the response.  This attribute may
be used if the full context is not required as part of the
response.

If the AuthorizationDecisionStatement includes the
xacml-context:Request element, then the returned context MUST
contain all data that affected the decision.  It is up to each
implementation whether the context is trimmed down to just the
values that "mattered" or whether the context was the superset of
all values known at the time of the decision whether they
affected the decision or not.

One reason for putting the input context in the assertion would
be to allow it to be saved by the PEP for audit purposes.

Anne
-- 
Anne H. Anderson             Email: 
Sun Microsystems Laboratories
1 Network Drive,UBUR02-311     Tel: 781/442-0928
Burlington, MA 01803-0902 USA  Fax: 781/442-1692
← Prev in month ← Prev in thread
Next in thread → Next in month →