<?xml version="1.0" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugzilla.globus.org/bugzilla/bugzilla.dtd">

<bugzilla version="3.2.3"
          urlbase="http://bugzilla.globus.org/bugzilla/"
          maintainer="bacon@mcs.anl.gov"
>

    <bug>
          <bug_id>6506</bug_id>
          
          <creation_ts>2008-10-27 12:10</creation_ts>
          <short_desc>SAML Holder-of-Key Assertion Request</short_desc>
          <delta_ts>2008-12-13 10:32:40</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>GridShib</product>
          <component>Roadmap</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>NEW</bug_status>
          
          
          <bug_file_loc>http://dev.globus.org/wiki/SAMLHoKAssertionRequest</bug_file_loc>
          
          
          <priority>P3</priority>
          <bug_severity>enhancement</bug_severity>
          <target_milestone>beta</target_milestone>
          <dependson>6505</dependson>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Tom Scavo">trscavo@gmail.com</reporter>
          <assigned_to name="Tom Scavo">trscavo@gmail.com</assigned_to>
          <cc>gridshib-dev@globus.org</cc>

      

      
          <long_desc isprivate="0">
            <who name="Tom Scavo">trscavo@gmail.com</who>
            <bug_when>2008-10-27 12:10:07</bug_when>
            <thetext>According to the SAML Holder-of-Key Assertion Request Profile, the SAML requester is the subject, that is, the subject self-issues a SAML request. The subject presents this request and an X.509 certificate to a SAML identity provider. The subject proves possession of the private key corresponding to the public key of the presented certificate and authenticates to the identity provider by unspecified means.

The identity provider consumes the request and issues a response. The identity provider binds data from the X.509 certificate to one or more assertions in the response.  The requester validates and consumes the response and outputs the holder-of-key assertion(s).

The SAML Holder-of-Key Assertion Request Profile depends on the SAML Holder-of-Key Assertion Profile:

http://wiki.oasis-open.org/security/SAMLHoKSubjectConfirmation

Also, the SAML Holder-of-Key Assertion Request Profile is related to the SAML Holder-of-Key Web Browser SSO Profile:

http://wiki.oasis-open.org/security/SamlHoKWebSSOProfile

An initial implementation of the latter was contributed by Joana M. F. Trindade through the Google Summer of Code (2008) program.  This implementation is the first phase of an implementation plan whose goal is to convert a campus credential (usually a username/password) into a SAML credential.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who name="Tom Scavo">trscavo@gmail.com</who>
            <bug_when>2008-12-13 10:32:40</bug_when>
            <thetext>The SAML V2.0 Holder-of-Key Assertion Request Profiles have been submitted to OASIS:

http://wiki.oasis-open.org/security/SAMLHoKAssertionRequest</thetext>
          </long_desc>
      
      

    </bug>

</bugzilla>