mace-opensaml-users - RE: Multiple subjects in SAML 1.x statement?
Subject: OpenSAML user discussion
List archive
- From: "Scott Cantor" <>
- To: <>
- Subject: RE: Multiple subjects in SAML 1.x statement?
- Date: Thu, 13 Dec 2007 14:23:21 -0500
- Organization: The Ohio State University
> That's true, but in the V1.1 schema the Subject element is a child
> element of the statement so in effect a single assertion can refer to
> multiple subjects.
This is structurally true but pragmatically "frowned on", not only because
it doesn't work in SAML 2, but because nobody came up with a use case for it
that didn't just involve sending different identifiers for the same person.
So, I wouldn't do it.
> I've written a profile for SAML V1.1 assertions that anticipates this
> and other differences between V1.1 and V2.0. We've implemented this
> profile using OpenSAML 1.1. The implementation enforces the "one
> subject" rule per assertion, for instance.
Yes, my general opinion is that using SAML 1.1 to do something you can't do
in SAML 2.0 would be a bad idea.
Have you thought about tossing that profile over the wall to OASIS?
-- Scott
- Multiple subjects in SAML 1.x statement?, Mu Li, 12/13/2007
- RE: Multiple subjects in SAML 1.x statement?, Scott Cantor, 12/13/2007
- Message not available
- Re: Multiple subjects in SAML 1.x statement?, Tom Scavo, 12/13/2007
- RE: Multiple subjects in SAML 1.x statement?, Scott Cantor, 12/13/2007
- Message not available
- Re: Multiple subjects in SAML 1.x statement?, Tom Scavo, 12/13/2007
- RE: Multiple subjects in SAML 1.x statement?, Scott Cantor, 12/13/2007
- Message not available
- Re: Multiple subjects in SAML 1.x statement?, Mu Li, 12/13/2007
- RE: Multiple subjects in SAML 1.x statement?, Scott Cantor, 12/13/2007
- Re: Multiple subjects in SAML 1.x statement?, Mu Li, 12/13/2007
- Message not available
- Re: Multiple subjects in SAML 1.x statement?, Tom Scavo, 12/18/2007
- Re: Multiple subjects in SAML 1.x statement?, Tom Scavo, 12/13/2007
- Re: Multiple subjects in SAML 1.x statement?, Tom Scavo, 12/13/2007
Archive powered by MHonArc 2.6.16.