ad-assurance - Re: [AD-Assurance] VERY drafty alternative means statement
Subject: Meeting the InCommon Assurance profile criteria using Active Directory
List archive
- From: David Walker <>
- To:
- Subject: Re: [AD-Assurance] VERY drafty alternative means statement
- Date: Fri, 09 Aug 2013 17:36:29 -0700
Interesting point. A principle I've always used is that credentials must be protected independent of where they may be stored or used. So, it really doesn't matter, for example, if a password is exposed by unencrypted LDAP between the IdP and the Verifier, or in some other authentication event. It's still the the credential, and it's still been exposed. David On Fri, 2013-08-09 at 23:22 +0000, Michael W. Brogan wrote: To more directly answer the question you asked, yes, the argument is for the “inclusive and” and under that interpretation you’d do LDAPS and be done. In other places in the IAP there are specific references to non-IdP apps, but not in section 4.2.5. Why did the authors call this out in some sections and not others? Just an oversight? Or maybe they had a narrower interpretation in mind and it was intentional. From: Michael W. Brogan
From: [] On Behalf Of Eric Goodman
From: [] On Behalf Of Michael W. Brogan
From: [] On Behalf Of David Walker
|
- [AD-Assurance] VERY drafty alternative means statement, David Walker, 08/08/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Michael W. Brogan, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Eric Goodman, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Michael W. Brogan, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Ron Thielen, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Michael W. Brogan, 08/09/2013
- Re: [AD-Assurance] VERY drafty alternative means statement, David Walker, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Michael W. Brogan, 08/09/2013
- Re: [AD-Assurance] VERY drafty alternative means statement, Ann West, 08/12/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Michael W. Brogan, 08/09/2013
- Re: [AD-Assurance] VERY drafty alternative means statement, David Walker, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Eric Goodman, 08/09/2013
- RE: [AD-Assurance] VERY drafty alternative means statement, Michael W. Brogan, 08/09/2013
Archive powered by MHonArc 2.6.16.