[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Subject: RE: [security-services] New (minor) Issue: AuthNMethod,not Confi rmationMethod in AuthNQu ery
I agree with the changes listed by Hal, but I now find the lines 1286-1290 to be confusing and partially redundant with section 3.4.4. These lines talk about how to generate the response and discusses matching the <ConfirmationMethod> elements. This is what 3.4.4 already discusses in a more specific way. Since 3.4.4 talks about matching confirmations, should these lines be replaced with text describing how to match the <AuthenticationMethod>'s which were described just above it? I'd suggest some text, but I've got to run right now.
And just to make sure I still understand this...
Since <AuthenticationQuery> extends <SubjectQueryAbstractType>, I can specify both <AuthenticationMethod>'s and <ConfirmationMethod>'s in my query, right? At least that's how I read the schema -- the <ConfirmationMethod> elements are part of the <Subject> element (by extension) and the <AuthenticationMethod> elements are part of the <AuthenticationQuery>.
Thanks!
Rob Philpott RSA Security Inc. The Most Trusted Name in e-Security Tel: 781-515-7115 Mobile: 617-510-0893 Fax: 781-515-7020
-----Original Message-----
In the AuthenticationQuery, it is possible to provide an optional ConfirmationMethod. I believe the intent here was to specify an AuthenticationMethod. (Prateek says this is an old bug that never got fixed.) Spcifically, line 1282, 1298 and 2324 change "ConfirmationMethod" to "AuthenticationMethod" line 1285 change "confirmation" to "authentication" Hal |
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [Elist Home]
Powered by eList eXpress LLC