mace-opensaml-users - RE: How to create authentication using SAML and Security concerns!
Subject: OpenSAML user discussion
List archive
- From: "Wilcox, Mark" <>
- To: <>, <>
- Subject: RE: How to create authentication using SAML and Security concerns!
- Date: Fri, 16 May 2003 12:11:46 -0400
Title: How to create authentication using SAML and Security concerns!
I'm not sure you know what you're looking for :).
SAML provides a standard way for passing authorization statements around.
It appears that much of this information is going to be demographic in nature
(This request is from Mark Wilcox, he works at WebCT, Inc. We validated this
based on his username and password verified against our LDAP server). This data
is signed (and optionally completely encrypted) using Public Key
Infrastructure -- normally X.509, not PGP (similar concept, different protocol).
What PKI provides is a greater level of trust between 2 sites so that you
can more reliably base security decisions based on information provided from the
external site via SAML.
The risk factor in SAML is really no different than any other system like
this. And the risk factors are IMHO outweighed by the benefits.
Mark
|
- How to create authentication using SAML and Security concerns!, tejaharini, 05/11/2003
- RE: How to create authentication using SAML and Security concerns!, Scott Cantor, 05/12/2003
- <Possible follow-up(s)>
- RE: How to create authentication using SAML and Security concerns!, Wilcox, Mark, 05/16/2003
Archive powered by MHonArc 2.6.16.