Skip to Content.
Sympa Menu

assurance - Re: [Assurance] silver, 2-factor, password requirements

Subject: Assurance

List archive

Re: [Assurance] silver, 2-factor, password requirements


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: "" <>
  • Subject: Re: [Assurance] silver, 2-factor, password requirements
  • Date: Fri, 30 Nov 2012 16:23:06 +0000
  • Accept-language: en-US

On 11/30/12 11:11 AM, "Jones, Mark B"
<>
wrote:

>Tom,
>Are you contradicting Tom and saying that identity proofing is in fact
>required?

No, he's saying that isn't a property of the information being
communicated to the RP. All the RP cares about is that "the people who can
login with an assertion containing the identifiers A, B, or C are the
appropriate people. It cares nothing about who those people are in the
real world.

It is a decision of the asserting party how and whether to associate those
accounts with specific people and how it would go chase them down if they
did something bad. All the liability is with the IdP.

This is a common model whenever the resources involved at the RP are
really not owned by the RP, but are owned by the IdP. That's what Tom
referred to as SaaS.

-- Scott





Archive powered by MHonArc 2.6.16.

Top of Page