RFC extensions to Shibboleth

Leif Johansson leifj at sunet.se
Tue Sep 4 08:53:14 EDT 2012


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


> We would really appreciate feedback on the work done in order to 
> understand with the community if the direction taken is good or if
> some review may be suggested. Thanks and regards,

My problem is that this assumes that the IdP uses username & password.

This is an increasingly invalid assumption, for instance as sites roll
out ADFS2 which uses Negotiate instead of Basic.

The point of SAML is to have an abstraction layer, so that relying
parties could move beyond passwords.

This breaks that abstraction layer.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://www.enigmail.net/

iEYEARECAAYFAlBF+boACgkQ8Jx8FtbMZndtBACeKFfmFkYZJhBggKX/tho4nTR8
hoUAn2GhY1DLuh8B0IwE3ICbOA/mGTiI
=P5A8
-----END PGP SIGNATURE-----


More information about the dev mailing list