atom feed17 messages in org.oasis-open.lists.security-servicesRE: [security-services] AssertionCons...
FromSent OnAttachments
Mishra, PrateekAug 25, 2004 9:44 am 
Conor P. CahillAug 25, 2004 10:06 am 
Scott CantorAug 25, 2004 10:16 am 
Scott CantorAug 25, 2004 10:19 am 
Conor P. CahillAug 25, 2004 10:31 am 
Scott CantorAug 25, 2004 11:02 am 
Conor P. CahillAug 25, 2004 11:20 am 
Scott CantorAug 25, 2004 11:28 am 
Conor P. CahillAug 25, 2004 11:42 am 
Scott CantorAug 25, 2004 11:51 am 
Conor P. CahillAug 25, 2004 9:13 pm 
Scott CantorAug 25, 2004 9:24 pm 
Conor P. CahillAug 25, 2004 9:26 pm 
Scott CantorAug 25, 2004 9:31 pm 
Scott CantorAug 25, 2004 9:39 pm 
Mishra, PrateekAug 30, 2004 1:24 pm 
Scott CantorAug 30, 2004 1:28 pm 
Subject:RE: [security-services] AssertionConsumerServiceIndex vs. AssertionConsumerURL
From:Conor P. Cahill (conc@aol.com)
Date:Aug 25, 2004 11:42:21 am
List:org.oasis-open.lists.security-services

Scott Cantor wrote on 8/25/2004, 2:29 PM:

So here's how it's an issue:

<SubjectConfirmationData Recipient="URL submitted by bad provider">

Ahh... makes more sense now. I thought the Recipient would have a ProviderID in it, not the URL that the response was sent to.

I'm not sure we want the URL in there in cases where this assertion isn't being used on an browser based SSO transaction. Need to think about this some more.

Conor