SOA Security

Cantor, Scott cantor.2 at osu.edu
Mon Feb 23 13:38:38 EST 2015


On 2/23/15, 6:16 PM, "Emilio Penna" <emilio.penna at seciu.edu.uy> wrote:

>I found this helpful, when I was dealing with an "intermediary" scenario.
>
>SAML V2.0 Condition for Delegation Restriction
>http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-delegation-cs-0
>1.pdf

That's part of doing this properly, yes, but it's a very small part of an 
implementation. It's primarily needed to prevent inadvertent acceptance of 
delegated access, but for most services, they just don't care that much, 
and most non-Shibboleth SPs will never even notice it (and are therefore 
buggy, by accepting an unknown condition as valid).

-- Scott



More information about the users mailing list