← Prev in month ← Prev in thread
Next in thread → Next in month →

[security-services] Proposed Text and Location for HolderOfKey andSenderVouches (NOT E commentary at start)

From
Mishra, Prateek <>
Date
2002-04-05T20:31:57+00:00
ID
Thread
[security-services] Proposed Text and Location for HolderOfKey andSenderVouches (NOT E commentary at start)
<Comment>

I have taken the consistent 
approach that all the confirmation method identifiers are
defined outside 
profiles (the profile just "uses" them) in a new section (section 5). 
I 
have generated a single section with the following text. The text for Holder Of 
Key closely mimics material from [DSIG] to ensure that use of secret or 
public-private key pair are both included. 

</Comment>

 

<add>

 

5 Confirmation Method 
Identifiers

 

5.1.1 Holder Of 
Key

 

URI:  

urn:oasis:names:tc:SAML:1.0:cm:holder-of-key

The element 
<SubjectConfirmationData> value MUST be a <ds:KeyInfo> 
element.
As described in [DSIG], the <ds:KeyInfo> element 
holds information that enables an
application to obtain a key needed to 
validate a signature.  The subject of the assertion 
is the party that can 
demonstrate that it is the holder of the key used to create said 
signature.

5.1.2 Sender Vouches

URI:

urn:oasis:names:tc:SAML:1.0:cm:sender-vouches

Indicates that no other information is available about the 
context of use of the assertion. The relying party SHOULD utilize other means to determine if it should process the assertion 
further. 

 

5.1.3 SAML Artifact

 

URI: 

urn:oasis:names:tc:SAML:1.0:cm:artifact-01

 

The subject of the 
assertion is the party that can present a SAML artifact, which
the relying 
party MUST use to obtain the assertion from the party that 
created
the artifact. See also Section 4.1.1.1.

 

5.1.4 
Bearer 

 

URI:

urn:oasis:names:tc:SAML:1.0:cm:bearer

The subject of the assertion 
is the bearer of the assertion. See also Section 4.1.2.1.

 

 

 

 

 

URI:

 

urn:
← Prev in month ← Prev in thread
Next in thread → Next in month →