Skip to Content.
Sympa Menu

mace-opensaml-users - RE: [OpenSAML] local part cannot be "null" when creating a QName during unmarshalling an Assertion object

Subject: OpenSAML user discussion

List archive

RE: [OpenSAML] local part cannot be "null" when creating a QName during unmarshalling an Assertion object


Chronological Thread 
  • From: "Scott Cantor" <>
  • To: <>
  • Subject: RE: [OpenSAML] local part cannot be "null" when creating a QName during unmarshalling an Assertion object
  • Date: Fri, 5 Mar 2010 16:24:37 -0500
  • Organization: The Ohio State University

> Scott; Do you mean to say pass "urn:oasis:names:tc:SAML:2.0:cm:sender-
> vouches" instead of "urn:oasis:names:tc:SAML:2.0:cm:bearer" in the SAML
> Assertion, as the primary Identity Provider is not generating this
> Assertion??

Yes, because "bearer" means anybody with possession of it can use it. That's
not what this use case is about. It's about unilaterally trusting the client
to say whatever it wants to say, and no other relying party should think it
should accept the assertion unless it also trusts its client implicitly.

In other words, the rules aren't in the assertion, they're part of the out
of band arrangement.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page