shibboleth-dev - Re: authentication authority
Subject: Shibboleth Developers
List archive
- From: Tom Scavo <>
- To: Scott Cantor <>
- Cc:
- Subject: Re: authentication authority
- Date: Thu, 13 Oct 2005 18:13:32 -0400
- Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:content-disposition:references; b=rc3yHoZhO/n7xfrdEXB+SufldtEDbtnobRKzHS1ONhEAhIoZexCSWI5RuAuBHUntS+w7P/+wQ4MS7/KPR82dCGdo0X+IUEzRkQ9l0pvLBb13w2r3OUXvibWgYDwHrqKJ609A4VM5fmIAnkpqJXxRDywV4XaO91GaJ/Kqb/J5k4M=
On 10/13/05, Scott Cantor
<>
wrote:
> > 1) A MyProxy Client, on behalf of the Grid User, sends a MyProxy
> > Protocol request to the MyProxy Server. The Grid User's
> > authentication credentials (username/password) are included with the
> > request.
>
> What does this protocol consist of?
You don't want to know... ;-)
> I just wonder
> if it isn't better to do what I originally suggested, use a SAML assertion
> issued by the IdP to authenticate to the MyProxy service. That of course
> also gets you a subject identifier for the cert that will be valid at the
> AA.
Excellent idea! I'll look at that more closely and see what the issues are.
> One thing to note here...this all works more or less fine but *only* because
> we actually have a bit of a long-standing bug in that we don't really issue
> transient IDs to specific SPs. So there's no SP check made when a query
> comes in. Really there should be.
Good point. This anticipates a question Tom Barton had on the
GridShib call today. Thanks for mentioning this.
Scott, your comments and suggestions continue to be invaluable.
Thanks for taking the time.
Tom
- Re: authentication authority, (continued)
- Re: authentication authority, Von Welch, 10/07/2005
- RE: authentication authority, Scott Cantor, 10/07/2005
- Re: authentication authority, Chad La Joie, 10/07/2005
- Re: authentication authority, Von Welch, 10/09/2005
- Re: authentication authority, Von Welch, 10/07/2005
- Re: authentication authority, Tom Scavo, 10/08/2005
- Re: authentication authority, Scott Cantor, 10/08/2005
- Re: authentication authority, Tom Scavo, 10/10/2005
- RE: authentication authority, Scott Cantor, 10/10/2005
- Re: authentication authority, Tom Scavo, 10/12/2005
- RE: authentication authority, Scott Cantor, 10/13/2005
- Re: authentication authority, Tom Scavo, 10/13/2005
- Re: authentication authority, Scott Cantor, 10/13/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Brent Putman, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Brent Putman, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- Re: authentication authority, Tom Barton, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
- RE: authentication authority, Scott Cantor, 10/14/2005
- Re: authentication authority, Tom Scavo, 10/14/2005
Archive powered by MHonArc 2.6.16.