RE: [saml-dev] encrypting saml protocol messages

From
Hal Lockhart <>
Date
2011-10-27T14:58:16+00:00
ID
b9543ef0-2457-40de-ac92-1811563251ae@default
Thread
RE: [saml-dev] encrypting saml protocol messages
The 
SAML request/response protocol is carried over SOAP which means you can use 
either WS-Security or TLS to encrypt the message in transit (and in the case of 
WS-Security, keep the encrypted message around if you wish.) When Assertions are 
returned over HTTP, TLS may be used. The SAML TC did not see a need to difine 
yet another way to do the same thing. The assumption was that if you wish to 
persist data which needs to be confidential, that data will be contained in the 
Assertion.

 

What 
is your use case?

 

Hal

  
-----Original Message-----
From: Yang, Gang USA CTR (US) 
  [mailto:]
Sent: Monday, October 24, 2011 3:09 
  PM
To: 
Subject: [saml-dev] 
  encrypting saml protocol messages

  

  
Hi,

  
 

  
I'm trying to implement Web SSO 
  profile and wondering why  SAML 2.0 did not define the encryption of SAML 
  procotol messages (request/response), but only encryption of the SAML 
  assertion and some sub elements. Can any one shed some light on 
  this?

  
 

  
Thanks,

  
Gang