mace-opensaml-users - Re: Use SAML Assertion as Kerberos Ticket
Subject: OpenSAML user discussion
List archive
- From: "Pham Hoai Van" <>
- To: <>
- Subject: Re: Use SAML Assertion as Kerberos Ticket
- Date: Thu, 24 Mar 2005 00:21:53 +0700
Relace Kerberos Ticket by SAML Assertion may not feasible. Ok, but using publickey is really slow down performce of the system. And I really like the security model of Kerberos with the use of symmetric key. I will think about defining the format of Kerberos based on XML.
Thanks all.
----- Original Message ----- From: "Tom Scavo" <>
To: "Pham Hoai Van"
<>
Cc:
<>
Sent: Wednesday, March 23, 2005 10:34 PM
Subject: Re: Use SAML Assertion as Kerberos Ticket
On Wed, 23 Mar 2005 20:00:53 +0700, Pham Hoai Van
<>
wrote:
Because Kerberos Ticket is not xml-based, so i want a replacement of it with
other xml-based message.
Is it feasible with SAML Assertion ?
A Kerberos principal name can be used to identity a SAML subject (cf.
section 8.3.5 of [SAML2Core]) so yes, a SAML assertion can be
associated with a Kerberos ticket. I'm not sure what you're up to,
however. If you're more interested in web services than browsers, you
might want to take a look at [WSSKerberosProfile] as well.
Hope that helps,
Tom
[SAML2Core] http://www.oasis-open.org/committees/download.php/11898/saml-core-2.0-os.pdf
[WSSKerberosProfile]
http://www.oasis-open.org/committees/download.php/8266/oasis-xxxxxx-wss-kerberos-token-profile-1%200.pdf
- Use SAML Assertion as Kerberos Ticket, Van Hoai, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Tom Scavo, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Pham Hoai Van, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Derek Atkins, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Scott Cantor, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Tom Scavo, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Pham Hoai Van, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Scott Cantor, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Derek Atkins, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Scott Cantor, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Derek Atkins, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Scott Cantor, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Derek Atkins, 03/23/2005
- RE: Use SAML Assertion as Kerberos Ticket, Scott Cantor, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Pham Hoai Van, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Derek Atkins, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Pham Hoai Van, 03/23/2005
- Re: Use SAML Assertion as Kerberos Ticket, Tom Scavo, 03/23/2005
Archive powered by MHonArc 2.6.16.