mace-opensaml-users - RE: CRL question
Subject: OpenSAML user discussion
List archive
- From: "Christopher Brown" <>
- To: <>
- Cc: <>
- Subject: RE: CRL question
- Date: Mon, 24 Apr 2006 08:16:45 -0400
Title: RE: CRL question
You might want to take a look at OCSP. From:
[mailto:] It's for
the authentication of users. The situation is the following: The users
can login to our website via a Federal service of the belgian government. Thus,
all the login is not part of our application. The federal service sends (posts)
a SAML message to our application with the info of the user and the status of
the login (success, failed, etc.). We need to check the validity of the saml
message before allowing the user to enter to our website. We manage quite
sensitive information, so we cannot ignore the CRLs. Since this website is
intended for the clients, 20-30 seconds waiting for the login is in the limit
of the acceptable. That's why we want to (if possible) cache the CRLs, for
diminishing that waiting time. Thanks,
-----Original
Message----- My
experience is that most folks just pretend that CRLs don't exist Are you
authenticating users or system entities with your -Walter
On Apr
21, 2006, at 6:54 AM, wrote: >
|
- CRL question, miro . casanova, 04/21/2006
- Re: CRL question, Walter Hoehn, 04/21/2006
- <Possible follow-up(s)>
- RE: CRL question, miro . casanova, 04/24/2006
- RE: CRL question, Christopher Brown, 04/24/2006
Archive powered by MHonArc 2.6.16.