Opinions on SIDP-570?

David Bantz dabantz at alaska.edu
Mon Feb 18 12:48:23 EST 2013


I was coincidentally puzzling over this the other day.  

Are we in effect saying encryption of the response is enough protection from service spoofing?

On Mon, 18 Feb 2013, at 08:20 , "Cantor, Scott" <cantor.2 at osu.edu> wrote:

> since we don't generally require signed requests from the SPs we do
> know, that doesn't exactly scream consistency.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20130218/82dea36d/attachment.html 


More information about the dev mailing list