Skip to Content.
Sympa Menu

assurance - Re: [Assurance] silver, 2-factor, password requirements

Subject: Assurance

List archive

Re: [Assurance] silver, 2-factor, password requirements


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: "" <>
  • Subject: Re: [Assurance] silver, 2-factor, password requirements
  • Date: Thu, 29 Nov 2012 22:59:13 +0000
  • Accept-language: en-US

On 11/29/12 5:07 PM, "Tom Scavo"
<>
wrote:

>The user isn't the responsible party in this case since we have a signed
>agreement with the user's organization. This is basically how it works
>with most (all?) SaaS apps.

And it's left to the organization to decide how much they care about the
identity of their users, but that's not a cross-organizational assurance
requirement.

Where this breaks down a bit is trying to federate access to resources in
that scenario as opposed to just running silos. Mostly it's still left to
the users owning resources to decide how to care about the binding between
identifiers and people. The RP doesn't care.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page