shibboleth-dev - RE: authentication authority
Subject: Shibboleth Developers
List archive
- From: "Scott Cantor" <>
- To: "'Tom Scavo'" <>, <>
- Subject: RE: authentication authority
- Date: Thu, 6 Oct 2005 11:30:22 -0400
- Organization: The Ohio State University
It seems like what you're really trying to do is address a pair of issues,
and I think inventing a new protocol to get an authentication assertion and
sticking that in a certificate is probably overkill for both.
You seem to be aiming at:
- supporting pseudonymity using transient subject names
- getting a subject name into the certificate that will be understood by the
SAML authority later
Those goals are separable, of course.
One way of doing this that solves both issues is essentially what the
LionShare CA does, using the self-encrypted handle generator to build an ID
at the CA that can be decrypted by the SAML authority. Personally, I think
that's the easiest solution.
Alternatively, this seems more like a use case for the SAML 2
NameIdentifierMapping protocol, perhaps extended a bit. What you want isn't
an authentication assertion, you just want a NameID that is valid for a
particular principal in a particular format. Then you can just put that name
in the certificate subject.
-- Scott
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- Re: authentication authority, RL 'Bob' Morgan, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Tom Scavo, 10/05/2005
- RE: authentication authority, Scott Cantor, 10/06/2005
- Re: authentication authority, Von Welch, 10/07/2005
- RE: authentication authority, Scott Cantor, 10/07/2005
- Re: authentication authority, Chad La Joie, 10/07/2005
- Re: authentication authority, Von Welch, 10/09/2005
- Re: authentication authority, Von Welch, 10/07/2005
- Re: authentication authority, Tom Scavo, 10/08/2005
- Re: authentication authority, Scott Cantor, 10/08/2005
- Re: authentication authority, Tom Scavo, 10/10/2005
- RE: authentication authority, Scott Cantor, 10/10/2005
- Re: authentication authority, Tom Scavo, 10/12/2005
- RE: authentication authority, Scott Cantor, 10/13/2005
- RE: authentication authority, Scott Cantor, 10/06/2005
- Re: authentication authority, Tom Scavo, 10/05/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
- Re: authentication authority, Von Welch, 10/04/2005
- RE: authentication authority, Scott Cantor, 10/04/2005
Archive powered by MHonArc 2.6.16.