> Rich, I'm just asking that the ids (whatever they look like) be defined in
> the Appendix before the dry run (and it would be nice if the suffix portion
> of the rdns were the same). E.g.,
I think we're in agreement except that instead of uid I want to use CN,
CommonName. As in
cn=Alice, o=entrust.com
cn=demo.entrust.com, o=entrust.com
cn=Bob, o=entrust.com
(the middle one is an SSL cert; the other two are end-entities.) Is this
okay?
> I'm not sure what you mean by storing an email addres in the subjectAltName
> as this attribute is not present in the Saml NameID when the format is an
> x509 subject name?
I'm implying that the hacky "email" RDN won't be used.
/r$
--
Rich Salz Chief Security Architect
DataPower Technology http://www.datapower.com
XS40 XML Security Gateway http://www.datapower.com/products/xs40.html
XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html