Document:
Shared Credential Use Case Discussion

Draft (A preliminary unapproved sketch, outline, or version.)

Details

Submitted By Paul Madsen on 2006-04-11 4:12 pm UTC

Publication Type

None at this time.

Group / Folder

OASIS Security Services (SAML) TC / A.9: V2.0 Working Documents / Input Submissions

Modified by

Not modified.

Copy

This document is not a copy.

Technical Contact

None at this time.

Download Count

919

Download Agreement

None at this time.

Description

An IDP will be unable to assert to an SP a particular identity for a user if that user authenticates to the IDP
using a credential known to be shared with other users. If the credential by which a user authenticates
does not uniquely identify them (e.g. a phone at home, access to a workstation, PPPoE authentication
etc) then the IDP will be unable to assert anything beyond the fact that the user was one of the set of
individuals that shared that credential. An SP may deem such an assertion as insufficient for enabling
access to resources associated with a particular individual identity and so may request of the IDP an
assertion characterized by a credential unique to that individual.