assurance - Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management
Subject: Assurance
List archive
Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management
Chronological Thread
- From: Tom Barton <>
- To:
- Subject: Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management
- Date: Tue, 27 Nov 2012 09:28:37 -0600
Dave, The language in 4.2.4.5 is intentionally not specific as to nature of measures, nor is there an adjective in front of "verify" to qualify how perfectly. Personally, I picture a range of technical and non-technical measures being used at IdPOs in good faith efforts to protect their users, knowing that perfect protection is generally impossible or infeasible. In the case of a self-serve workflow in which the user requests a single-use secret be delivered using a per-registered out of band delivery mechanism, like SMS to a cellphone, it could be sufficient to protect the web site on which the user makes that request with an SSL cert that can be validated and has a subject name in a namespace administered by the IdPO. Make sense? Tom On 11/27/2012 9:10 AM, David Langenberg
wrote:
Well, today (pre anything silver) we have the individual call into the helpdesk, do a very basic Q/A session over the phone with them, and if we think they're legit, give them the single-use secret. Obviously that doesn't work for silver, so instead the support person will have a button which will transmit the secret to the individual's addresses of record. Now, in this flow, yes, the user will be on the phone so the support person could say, "here comes a text message to your cell / email." The user could also read the message to the support person & verify that way. In the self-service workflow though, the app will tell the user about the message with the secret, but there would be no way short of calling the helpdesk or seeing if the secret worked for the purposes or regaining control of the account to verify that the IDPO is the source of the message. |
- [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Ann West, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, David Langenberg, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Ann West, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Ann West, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, David Langenberg, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Tom Barton, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, David Langenberg, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Jones, Mark B, 11/30/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, David Langenberg, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Tom Barton, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, David Langenberg, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Eric Goodman, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Bradner, Scott, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Eric Goodman, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Bradner, Scott, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Eric Goodman, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Ann West, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, Bradner, Scott, 11/16/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, arlene Allen, 11/16/2012
- [Assurance] Update: Request for Comment: IAP 4.2.4 Credential Issuance and Management, Ann West, 11/27/2012
- Re: [Assurance] Request for Comment: IAP 4.2.4 Credential Issuance and Management, David Langenberg, 11/16/2012
Archive powered by MHonArc 2.6.16.