Signing authN requests: yea or nay?
Erdos, Marlena
marlena_erdos at harvard.edu
Tue Sep 24 17:51:27 EDT 2013
Scott wrote:
> The purpose of signing requests in the original specification process was
auditing, not an attack mitigation.
>
Hmm. While I don't entirely remember the discussions :-), I do remember
that the original spec only had an artifact being returned as a response
to the authentication request, and not potentially interesting
information about the user.
Authentication of the requester definitely got done on the attribute
request :-).
Thx,Marlena
More information about the users
mailing list