Signing authN requests: yea or nay?

Erdos, Marlena marlena_erdos at harvard.edu
Tue Sep 24 17:51:27 EDT 2013


Scott wrote:
> The purpose of signing requests in the original specification process was
auditing, not an attack mitigation.
>

Hmm.  While I don't entirely remember the discussions :-), I do remember
that the original spec only had an artifact being returned as a response
to the authentication request,  and not potentially interesting
information about the user.

Authentication  of the requester definitely got done on the attribute
request :-).

Thx,Marlena 



More information about the users mailing list