> We're not creating end-entity certs for the users we're talking about
> here. This is simply a discussion of what will be in the NameID of a
> Subject of an Assertion that will contain the AuthnStatement indicating
> the user logged in with a password.
okey. i might have been a bit confused by the questions.
> Our user repository is built around looking users up by uid, not CN. So
> for us, I'd prefer to stick with the uid. I'm sure we can hack it to
> work with CN's, but I'd rather not.
i actually don't care all that much. i was just trying to follow what was
done last year. shrug, whatever works for folks.
/r$
--
Rich Salz Chief Security Architect
DataPower Technology http://www.datapower.com
XS40 XML Security Gateway http://www.datapower.com/products/xs40.html
XML Security Overview http://www.datapower.com/xmldev/xmlsecurity.html