RE: XKMS and X509v3 attributes, where to put them in?

In a Web Services context, one could look at starting with an X.509 token
and then exchanging that, through WS-Trust, for a related SAML token
containing the role information. 

Michael, Manuel, does that sound like it would suit your problem scenario?

Regards, Ed
_____________________
Ed Simon <edsimon@xmlsec.com>
Principal, XMLsec Inc. 
(613) 726-9645 

Interested in XML, Web Services, or Security? Visit "http://www.xmlsec.com".


New! "Privacy Protection for E-Services" published by Idea Group (ISBN:
1-59140-914-4 for hard cover, 1-59140-915-2 for soft cover). 
Includes a chapter, by Ed Simon, on "Protecting Privacy Using XML, XACML,
and SAML".
See the Table of Contents here: "http://tinyurl.com/rukr4".

-----Original Message-----
From: www-xkms-request@w3.org [mailto:www-xkms-request@w3.org] On Behalf Of
Stephen Farrell
Sent: October 17, 2006 08:14
To: Michael Wilde
Cc: www-xkms@w3.org
Subject: Re: XKMS and X509v3 attributes, where to put them in?




Michael Wilde wrote:
> This raises the question: is there any standardized request/response 
> protocol available for the communication with an Attribute Authority yet?

SAML.

S.

Received on Tuesday, 17 October 2006 17:01:49 UTC