shibboleth-dev - Re: authentication authority
Subject: Shibboleth Developers
List archive
- From: Tom Scavo <>
- To: Scott Cantor <>
- Cc: Shibboleth Development <>
- Subject: Re: authentication authority
- Date: Fri, 30 Sep 2005 14:31:46 -0400
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=PlCu6iJVyPRhC7lo64+NwC1jtv2drkB6asFb9pUW2cnbL179Wtf/+Yunsy98jGdqtREghy0jhxRkUC5CiDg4jaIhhAFD6fm2NZYyLUZm8AeG5PVHxQ0QAuzi7/piOM+yxn6s9B7+2GiS1BXHreYws7X11T/XfqggbKV4crtdDY4=
On 9/30/05, Scott Cantor
<>
wrote:
>
> It seems like it suffers from the same basic problem as all the other use
> cases I've seen for the query do...why would you do it? If you've already
> authenticated to the grid service, why does it need a SAML assertion?
Well, our use case requires the value of AuthenticationMethod so the
first thought was to obtain an authentication assertion. I can see
now, however, that may be fruitless since MyProxy will have to
communicate AuthenticationMethod when it registers the DN, so it may
as well just store AuthenticationMethod in the cert itself.
> About the only reason I could think of would be to do something with the
> AuthnContext feature, so it would be a SAML 2.0 thing,
We're stuck on SAML 1.1 for the foreseeable future, so
AuthenticationMethod is the best we can hope for.
> and it would still be
> something you could ship as a set of attributes anyway.
Yes, I suppose so. Either that or put it in the cert.
> There is a lot of downside to SAML separating AuthnStatement from
> AttributeStatement. In practice, I think it doesn't work real well, and
> that's one reason AuthnQuery always seemed silly to me.
You're right, I guess. It doesn't make much sense to process an
authentication assertion for a single attribute value. If the
authentication assertion had some other use, that might be a different
story.
Thanks,
Tom
- authentication authority, Tom Scavo, 09/29/2005
- RE: authentication authority, Scott Cantor, 09/30/2005
- Re: authentication authority, Tom Scavo, 09/30/2005
- RE: authentication authority, Scott Cantor, 09/30/2005
Archive powered by MHonArc 2.6.16.