mace-opensaml-users - RE: A suggestion about digital signatures
Subject: OpenSAML user discussion
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: A suggestion about digital signatures
- Date: Wed, 19 Sep 2007 11:09:27 -0400
- Organization: The Ohio State University
> My question is: for you, this token is correct?
I don't think it's generally acceptable to send two assertions in one token
element, no. I could be wrong though. There are no profiles for using
WS-Trust to do much of anything, other than Cardspace, so there's no answer
to that question. You can send a ham sandwich in there and it would be
"correct".
> in the ds:Signature I've the reference of the assertion twice:
I think that was a bug fixed a while back.
> When, in the client, I validate the assertions, the first, validates OK,
> the second (the attribute assertion) fails, because in the signature block
> there is still the response reference, that is not present in the
> <requestedSecurityToken>. How can I detach this signature in the identity
> provider?
A SAML signature is always inside what it signs and never references
anything else. There can't be two references, and there would never be a
reference to a response inside an assertion.
-- Scott
- A suggestion about digital signatures, Massimiliano Masi, 09/19/2007
- RE: A suggestion about digital signatures, Scott Cantor, 09/19/2007
- RE: A suggestion about digital signatures, George Stanchev, 09/19/2007
- RE: A suggestion about digital signatures, Massimiliano Masi, 09/20/2007
- RE: A suggestion about digital signatures, Massimiliano Masi, 09/21/2007
- RE: A suggestion about digital signatures, Scott Cantor, 09/21/2007
- RE: A suggestion about digital signatures, Massimiliano Masi, 09/22/2007
- RE: A suggestion about digital signatures, Scott Cantor, 09/23/2007
- RE: A suggestion about digital signatures, Massimiliano Masi, 09/22/2007
- RE: A suggestion about digital signatures, Scott Cantor, 09/21/2007
- RE: A suggestion about digital signatures, George Stanchev, 09/19/2007
- Re: A suggestion about digital signatures, Brent Putman, 09/19/2007
- RE: A suggestion about digital signatures, Scott Cantor, 09/19/2007
Archive powered by MHonArc 2.6.16.