← Prev in month ← Prev in thread
Next in thread → Next in month →

RE: [security-services-comment] Public review comments -saml-session-token-v1.0-csprd01

From
Hal Lockhart <>
Date
2011-04-28T22:28:12+00:00
ID
5cf77c34-452c-444b-902b-9382c0d7a4fd@default
Thread
RE: [security-services-comment] Public review comments -saml-session-token-v1.0-csprd01
The disposition of these comments is noted below.

> -----Original Message-----
> From: Paul Knight [mailto:]
> Sent: Friday, April 01, 2011 7:42 PM
> To: 
> Subject: [security-services-comment] Public review comments -
> saml-session-token-v1.0-csprd01
> 
> 
> Hi,
> 
> Most of this is minor editorial comments, with some comments 
> on the content.
> 
> line 12 - two right brackets on reference [RFC2965]].

corrected

> Section 1.2 - Five references using "et al." - each one is wrong -
> format is "J. Doe et al., Title of Work"

corrected

> line 23 - citing a working draft as a normative reference can delay
> progress to OASIS Standard

it has been clarified that the newly defined schema should not be listed as a normative reference - removed

> line 51 - need proper citation format for OASIS Standard

corrected in all six OASIS references

> line 86 - Figure 3 - since the flow depicted by the arrow DOES NOT
> happen, it might make sense to indicate this by a big "X" or something
> similar.

The flow DOES happen. The wording of the text was confusing. It has been improved.

> line 149 - missing period at end.

corrected

> Section 3 - might benefit from something like a ladder diagram to
> provide more detail on the sequence of messages flowing among SA,
> browser, and SC. This could be referenced in later sections.

The logical flow is always from SA to SC. It does not seem like a ladder diagram would make this clearer.

> line 283 - references in brackets should come before the period.

corrected

> Line 449 - remove word "use"

corrected

> line 450 - insert "the" before "past"

reworded

> 451 - lower case "R" in Running; it would be helpful to have a
> reference. Also, you might mean "published" instead of "publicized"?

corrected - non-normative reference added

> 455 - remove second "yet"

corrected

> 458 - Phrase ending in [RFC2965] is not a complete sentence.

reworded

> 460-464 - weak discussion - maybe re-write in terms of
> "man-in-the-middle attack"

paragraph reworded

> 465 - sever --> server

corrected

> 
> Useful spec!

Thank you,

Hal

> 
> Regards,
> Paul
> 
> -- 
> This publicly archived list offers a means to provide input to the
> OASIS Security Services (SAML) TC.
> 
> In order to verify user consent to the Feedback License terms and
> to minimize spam in the list archive, subscription is required
> before posting.
> 
> Subscribe: 
> Unsubscribe: 
> 
> List help: 
> List archive: 
> http://lists.oasis-open.org/archives/security-services-comment/
> Feedback License: 
> http://www.oasis-open.org/who/ipr/feedback_license.pdf
> List Guidelines: http://www.oasis-open.org/maillists/guidelines.php
> Committee: 
> http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=security
> 
>
← Prev in month ← Prev in thread
Next in thread → Next in month →