Extensibility of SAML 2 metadata
Keith Hazelton
hazelton at wisc.edu
Wed Jun 20 15:02:48 BST 2012
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Jun 20, 2012, at 08:59:33, Cantor, Scott wrote:
> On 6/20/12 9:04 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>>> I will note that this scenario is not SAML related, so maybe the answer
>>> is it doesn't belong in SAML metadata, extensions or not.
>>
>> It *is* SAML-related. Back-channel exchanges (artifact resolution and
>> attribute query, e.g.) are examples.
>
> Well, it may be similar, but that doesn't mean SAML. On the other hand,
> when you're doing security between servers with PKI, you have a handful of
> realistic choices:
>
> - manual (assuming you can control what keys are accepted at the two ends)
> - full on PKIX, including revocation or OCSP
> - half-ass it
> - metadata-like mechanisms for key management, involving custom code
>
> You can take a wild guess as to how most do it.
Yep, I can guess. Project Bamboo, for its part, wants to get away from manual (current practice) and is seriously consider a metadata-style mechanism. --Keith
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
Comment: GPGTools - http://gpgtools.org
iQEcBAEBAgAGBQJP4dgIAAoJEPXbVHOlscTvlvAH/R3ouoSZ0WEeOen0/+/R8gs1
NMkGS8h2MikD9Jpq7Z7wb4dx7PwTzrnelvA+2XsCOx2Y9+99eov7jRy5fjxMixrp
nuUGU4zZ9/Yj/1uUZvAwtBnaN2JiPCthCquaSWKvw9FD4pcpykvF2lKO44E7IsKm
oCFzzjlsMix22oi/Sy2zMRllSsls1pcfdEGDiLGLdiNxmUhZmBmrATeazt0LAAqs
xXyIfYR9z/j8B27X45DePtGSLUvUZhSHbsuWVRxqyMkEkTQBHuIMfdUTLzxBKfNw
JE0buj1yvdXv8/+MSbkfQSm3uR/LYKd/mX+/jQAFc+uSUOCGaewi3Yhs2Tu0cpE=
=d25P
-----END PGP SIGNATURE-----
More information about the users
mailing list