Re: SCVP-22 Open Issue: RFC 3379 Requirement #14
2006-02-01 14:50:32 GMT
The origin of that point was handled end of 2001 for about 6 months.
There were many
contributions, and you were actively involved.
I rediscovered that it was me to confirm the requirement for a textual
field following a debate with Denis who interpreted my request for an
'identifier' as such
whilst I was thinking somthing like expressed in a messagez from Tom:
Denis, Peter:
I have one question about this proposal. Is the object to be placed
into the response a transaction identifier or the RP's identifier? If it's
the RP's identifier, IMO it should be called something like "requestor's
claimed identity" and it should not be permitted to be altered by the
server, although it might be permitted to be dropped.
Tom Gindin
And I had this:
I have proposed in a different mail to Russ:
The protocol MUST provide a means to allow a client and a server
to indicate the participating entities.
I correct '... to indicate the identities of the entities participating in
the transction'.
and one may add "(depending on policy or application context)".
The discussion was stopped by Steve somehow
(Continue reading)
RSS Feed