OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

security-services message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Additions to PE65


Finally getting this done...

Here are the additional changes I would suggest to add to the list Rob
already supplied:

In core:

- Section 3.4.1.2, change the following text (adding the word optionally):

"In profiles specifying an active intermediary, the intermediary MAY examine
the list and return a <Response> message with an error <Status> and a
second-level..."

to

"In profiles specifying an active intermediary, the intermediary MAY examine
the list and return a <Response> message with an error <Status> and
optionally a second-level..."

- Section 3.8.3, change the following text (adding the word optionally):

"If the responder does not recognize the principal identified in the
request, it MAY respond with an error <Status> containing a second-level..."

to

"If the responder does not recognize the principal identified in the
request, it MAY respond with an error <Status>, optionally containing a
second-level...

Additional notes:

There are some statements in Bindings, but they're all worded as SHOULD, and
the code in question is just RequestDenied, which seems benign to me.

Lastly, we need to discuss, but I think one of Rob's changes should be
pulled back out. The change to section 3.7.3.2 seems like a bad idea. Single
logout is hard enough...I think it's important that indicating "partial
logout" be a mandatory thing. That's not a normal second-level code, and
it's used along with "Success", not as a failure mode. I think Rob misread
the intent there. The change itself as proposed wouldn't work anyway and
needs adjustment.

-- Scott

PS. I think part of another errata got accidentally embedded into the errata
doc for PE65 as well.




[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]