← Prev in month ← Prev in thread
Next in thread → Next in month →

RE: [saml-dev] Réf. : RE: [saml-dev] Question about logout

From
Scott Cantor <>
Date
2007-05-23T15:01:52+00:00
ID
002401c79d4b$43dccb80$cb966280$@
Thread
RE: [saml-dev] Réf. : RE: [saml-dev] Question about logout
> About this part :
> "If the IdP gets a request with some other value
> it should treat that as a failure, even if the IdP could *guess* which
> user they caller is talking about."
> 
> Where is this constraint indicated in the spec ?

It isn't because it isn't a constraint. How you identify principals in any
given context is implementation-specific. If you want to implement policies
controlling who can initiate operations around particular principals, you
can do that. It's up to customers what they expect products to do.

The only places there are specific mentions of the need to *not* allow for
identifier "fuzziness" in identifying principals is in subject matching for
some messages and in the NameIDMgmt protocol.

-- Scott
← Prev in month ← Prev in thread
Next in thread → Next in month →