encrypted assertions
Cantor, Scott
cantor.2 at osu.edu
Tue Aug 19 15:37:35 EDT 2014
On 8/19/14, 2:51 PM, "Mark K. Miller" <max at psu.edu> wrote:
>
>If an implementation claims to support SAML2 but does not support
>encrypted assertions, can that claim be completely correct?
In the sense of being conformant with any defined standard conformance
class, no, encryption is a MTI feature (mandatory to implement).
No vendor that doesn't support encryption is going to be aware that a
thing called SAML conformance exists of course.
As a deployment matter, nothing is going to require that somebody support
encryption. It's an optional-to-use feature that we happen to enable by
default.
>Phrasing the intent of my question another way (just in case I'm too
>confusing for anyone,) are encrypted assertions part of the SAML protocol
>spec?
Encryption is something you do to assertions or bits of data inside them,
it's not part of the protocol layer in SAML. It's defined by the core SAML
spec document, though.
>Those who know my protocol expertise will know anything much beyond
>single
>word, single syllable answers are likely to confuse me further.
Please read the above as "blorg".
-- Scott
More information about the users
mailing list