simpleSSO

Klingenstein, Nate nklingenstein at calstate.edu
Thu Dec 22 09:22:43 EST 2016


Rainer,

Thanks for taking the time to add your insights

> Both formats hold the implicit assumption that the claims that are of different provenance have been stitched together by the RA/CA respectively the federation operator. The RA/CA and FO are trust brokers, not finally authoritative. Although it is a convenient shortcut to think that the are.

To be honest, the deeper nuances in certificate authoristry are lost on me.  I wouldn't know how to take advantage of them, and I live by the convenient shortcut.  If you can think of a clever twist there that isn't confusing or hard, I'm eager to learn.

Whether you call a CA or federation operator a trust broker or a final authority is a little fuzzy to me.  I get a signed metadata file or a signed certificate.  I have exactly one place to check if it's good.  Even in the MDQ model, I have to pick my single authority, from what I understand.

The nice thing about bad certificates is that they blow up.  The deployer has to understand SAML to get the security.  The deployer has to understand TLS to get around the security.

> The notion of „pointing to“ at the level of cert and metadata is a question to be solved later at implementation time.

I think we're using different notions of "pointing to".  I mean "pointing to" like "has a pointer in it to", not "has a configuration file pointing to".  Do you have a field in your certificate that contains/points at your metadata, or a field in your metadata that contains/points to your certificate(s), or both?

Today, SAML metadata points at certificates in various ways through X509<blah> elements.  I want the link in the other direction.  I don't know why yet, but it feels completely right.  I have to think to get why.

> To build a model of such a policy you need to decompose the current SAML federation structure, both PKI and SAML-MetaIOP,  extract the claims and its assertions, and build a graph where claims are nodes and the assertions are edges. At this point directed associations start to make sense. 

Maybe I'm not reading this right, but if I am, I'll need to think about this in more detail before it sinks in.  I usually treat claims(in the WS-Trust sense) and assertions(in the SAML sense) as pretty similar.  Could you please rephrase?

Thanks for sharing your deep expertise,
Nate.


More information about the users mailing list