<?xml version="1.0" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugzilla.globus.org/bugzilla/bugzilla.dtd">

<bugzilla version="3.2.3"
          urlbase="http://bugzilla.globus.org/bugzilla/"
          maintainer="bacon@mcs.anl.gov"
>

    <bug>
          <bug_id>4500</bug_id>
          
          <creation_ts>2006-06-08 15:01</creation_ts>
          <short_desc>Enhancements to GridShib authentication assertion based query</short_desc>
          <delta_ts>2008-04-25 21:11:52</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>GridShib</product>
          <component>GT plugin</component>
          <version>0.4.1</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          
          
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Raj Kettimuthu">kettimut@mcs.anl.gov</reporter>
          <assigned_to name="Raj Kettimuthu">kettimut@mcs.anl.gov</assigned_to>
          <cc>gridshib-dev@globus.org</cc>
    
    <cc>rohder@mcs.anl.gov</cc>
    
    <cc>tfreeman@mcs.anl.gov</cc>
    
    <cc>trscavo@gmail.com</cc>
    
    <cc>vwelch@uiuc.edu</cc>

      

      
          <long_desc isprivate="0">
            <who name="Raj Kettimuthu">kettimut@mcs.anl.gov</who>
            <bug_when>2006-06-08 15:01:42</bug_when>
            <thetext>Enhance SAML Authn PIP so that when it finds SAML Assertion in Proxy Cert, it 
does the following validation: 
o Proxy cert must be a level 1 proxy cert (i.e. it&apos;s issuer is a EEC) 
o SAML Issuer must equal X509 Proxy Issuer 
o X509 Proxy Issuer (i.e. DN of EEC) must be on list of trusted SAML 
authentication authorities (new configuration option) 

Deliverables: 
• Secured version of PIP to extract SAML ssertion from proxy 
• Enhanced configuration documentation explaining how to configure trusted 
SAML authentication authorities</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who name="Raj Kettimuthu">kettimut@mcs.anl.gov</who>
            <bug_when>2006-06-21 12:15:16</bug_when>
            <thetext>This is completed and is available in GridShib for GT v0.4.1 (available at http://gridshib.globus.org/download.html). Documentation on how to configure this feature and more details are available in the admin guide at http://gridshib.globus.org/docs/gridshib-gt-0.4.1/admin-index.html.</thetext>
          </long_desc>
      
      

    </bug>

</bugzilla>