Skip to Content.
Sympa Menu

shibboleth-dev - RE: the big question at the end of this week's call.....

Subject: Shibboleth Developers

List archive

RE: the big question at the end of this week's call.....


Chronological Thread 
  • From: Scott Cantor <>
  • To: 'Keith Hazelton' <>,
  • Subject: RE: the big question at the end of this week's call.....
  • Date: Wed, 03 Dec 2003 20:18:08 -0500
  • Importance: Normal
  • Organization: The Ohio State University

> Would an approach like that below be a foundation on which to build
> into the app the ability to know the level of assurance of the current
> session and, at will, ask for a higher level. Seems like you'd need a
> round trip all the way back to the WebISO login step with information
> flowing and being processed both directions.

Liberty already supports this kind of thing, as do some Web-ISOs. SAML 2.0
will standardize this along with a possible vocabulary for describing
authentication requirements and context.

I believe there are certainly use cases for SOAP proxies and credential
translation, but I think they're what you use when don't have end-to-end
capability between the application and the identity provider or you simply
have intermediaries by design (delegation, for example).

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page