WS-Fed and WS-Trust support

Cantor, Scott cantor.2 at osu.edu
Mon Jul 22 13:41:46 EDT 2013


None of this has anything to do with the question that was asked.


On 7/22/13 1:33 PM, "Peter Williams" <pwilliams at rapattoni.com> wrote:

>academic system are missing what is now commodity in the windows world.
>("Commodity" is defined as I can program it, being a low-skill
>programmer, using only libraries such as dotNet).

No. What you're talking about is a non-trivial act, namely delegation.
Doing it right, let alone securely, is extremely difficult.

>for example, a Shib SP web app cannot submit a message on the Office 365
>email server (without having to have the users name/password.). In the
>windows  app-building world, active profiles are properly support (and
>relatively easy to implement).

And proprietary and undocumented. That is a false comparison.

> One can take the (SAML2 signed assertion) bearer token at that SP and
>use the Office 365's cloud STS (so-called federation gateway) to get a
>token suitable for attaching to the request message by the client agent
>responsible for consuming the "compose API" port offered by the site's
>Office365 subscription.

I don't believe for one minute those assertions are constructed properly
to allow for that.

-- Scott




More information about the dev mailing list