Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!
This says the user "user" authenticated in security domain "domain2.com" is authorised to access the file "http://server.domain1.com/index.htm". Typically this is a response from a PDP (policy decision point) to a PEP (policy enforcement point). This is an authorisation assertion.
You can also have an authentication assertion stating 'User1' was authenticated to security domain 'dom1' by, say, a digital certificate at time 'x' valid for period 'y'. And also an attribute assertion saying 'User1' has, say, an attribute 'credit limit' with a value of '$5000'.
Of course, there is a previously agreed and configured trust relationship behind the scenes.
Thanks peeps.... I have a problem here whereby SAML Assertion cannot be used as the browser is locked down (doh).... however, users could apparently "supply a SAML as and when required for particular times"... just wondered how, if this is security stipulated across identity and service domain providers, this could be supplied as and when..... accordingly, I am now told that the SAML Assertion code is verbally provided
Had a white noise moment... sorry and thanks again....
Comment