how important to you is conformance? of course you could implement
some proprietary, non-conformant mechanism that allows your web
service client (your "Resource A" on "SPA") to exchange the SPA
SSO assertion for a ws-security assertion. no?
On Thu Dec 08 07:50:15 PST 2005, w i l l
<> wrote:
> in a nutshell you can take either a liberty approach:
> http://www.projectliberty.org/specs/draft-liberty-idwsf-guidelines-v1.0-12.pdf
>
> or you can take a ws-* approach:
> ftp://www6.software.ibm.com/software/developer/library/ws-trust.pdf
>
>
>
> ---------------------------------------------------------------------
> This publicly archived list supports open discussion on
> implementing the SAML OASIS Standard. To minimize spam in the
> archives, you must subscribe before posting.
>
> [Un]Subscribe/change address: http://www.oasis-open.org/mlmanage/
> Alternately, using email: list-[un]
> List archives: http://lists.oasis-open.org/archives/saml-dev/
> Committee homepage:
> http://www.oasis-open.org/committees/security/
> List Guidelines:
> http://www.oasis-open.org/maillists/guidelines.php
> Join OASIS: http://www.oasis-open.org/join/