<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=Windows-1252">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
>> Before I head off to saml-dev about the OASIS spec, there seem to be three takes on the<br>
>>  matter.<br>
<br>
>There really aren't, and the errata doesn't enter into it. The errata has to do with SPs protecting themselves in their usage of the field, it has no ?>bearing on the actual requirement on the IdP to be 100% faithful in returning the value.<br>
<br>
>> * You make a crucial point: only the SP knows how to use the RelayState, which can<br>
>> create a disconnect between how IdPs handle the data and the errata's broader security<br>
>> intentions.<br>
<br>
>It does not, for the reason I stated. The spec requirements are clear and simple. </div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
They might be "clear and simple," except they flatly contradict you on this point. Own it<span class="_Entity _EType_OWA_HYPHEN _EId_OWA_HYPHEN _EReadonly_1" style="display: inline-block;"><span id="hyphen1" class="hyphen">—</span></span>I say this because
 I am sick of being patronized and condescended to on this list.  See below for a direct quote from the Errata.</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
>The errata is about other stuff that doesn't enter into this conversation at all unless one is analyzing the SP's approach to relay state, which is not >the IdP's problem.<br>
<br>
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Then how do you explain the following passage in the Errata that ex refer to identity providers in the following, and I quote from</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<a href="http://docs.oasis-open.org/security/saml/v2.0/errata05/os/saml-v2.0-errata05-os.html#__RefHeading__8196_1983180497" id="OWA560a44c3-94f3-9785-738c-f2e269864166" class="OWAAutoLink">SAML Version 2.0 Errata 05 (oasis-open.org)</a></div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<p class="elementToProof" style="margin-top: 0px; margin-bottom: 0px;"><span style="font-family: Arial, "sans-serif"; font-size: 10pt; color: black;">Add text to [SAMLBind] Section 3.1.1., before line 233</span><span style="font-family: ArialMT, "sans-serif"; font-size: 10pt; color: black;">:</span></p>
<p style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt;"><span style="font-family: Arial, "sans-serif"; font-size: 10pt; color: rgb(0, 0, 0);">New:</span></p>
<div style="background-color: silver; margin-right: 0.25in; margin-left: 0.25in; padding: 1pt; border-width: 1pt; border-style: solid; border-color: black;">
<p style="text-align: left; text-indent: 0px; background-color: silver; margin: 5.75pt 0in; padding: 0in; font-family: Arial, "sans-serif"; font-size: 9pt;">
<span style="color: rgb(0, 0, 0);">Some bindings that define a "RelayState" mechanism do not provide for end to end origin authentication or integrity protection of the RelayState value. Most such bindings are defined in conjunction with HTTP, and RelayState
 is often involved in the preservation of HTTP resource state that may involve the use of HTTP redirects, or embedding of RelayState information in HTTP responses, HTML content, etc. In such cases, implementations need to beware of Cross-Site Scripting (XSS)
 and other attack vectors (e.g., Cross-Site Request Forgery, CSRF) that are common to such scenarios.<br>
<br>
Implementations MUST carefully sanitize the URL schemes they permit (for example, disallowing anything but "http" or "https"), and should disallow unencoded characters that may be used in mounting such attacks. This caution applies to both identity and service
 provider implementations.</span></p>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
"This caution applies to both identity and service provider implementations." Not just service providers.</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
-F</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="text-align: left; text-indent: 0px; margin: 0in 0in 0.0001pt; font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
</body>
</html>