Skip to Content.
Sympa Menu

shibboleth-dev - RE: the big question at the end of this week's call.....

Subject: Shibboleth Developers

List archive

RE: the big question at the end of this week's call.....


Chronological Thread 
  • From: Scott Cantor <>
  • To: 'Barry R Ribbeck' <>
  • Cc: 'Keith Hazelton' <>, 'shib-dev' <>
  • Subject: RE: the big question at the end of this week's call.....
  • Date: Thu, 04 Dec 2003 16:33:03 -0500
  • Importance: Normal
  • Organization: The Ohio State University

> Target or a bridge function at the Origin. One thing that I would add is
> that if x509 is the requirement for the asserted auth method, then it
> would be useful on the target side to request the authenticator's public
> key for logging purposes.

That could be done either as a Shibboleth attribute or by exploring the
X.509 client cert approach whereby the target would actually accept the
certificate during TLS.

It would be a little weird, but I could imagine a target actually doing
client cert authn *and* the SAML profile, with the latter being used to
actually setup the session, but the former used to log the public key.

-- Scott




Archive powered by MHonArc 2.6.16.

Top of Page