Previous Topic: How SAML Token Multistep Authentication, Sender-Vouches Works

Next Topic: How Chain Authentication Service Model, Sender-Vouches with SSL-based Issuer Confirmation Works

How Chain Authentication Service Model, Sender-Vouches with Signature-Based Issuer Validation Works

This service model does not require the SAML assertion subject’s public and private keys bound to the request. A SAML token that uses the sender-vouches subject confirmation method is generated and used to authenticate the web service consumer by downstream web services; the token issuer’s identity is validated against its private key, which is bound to the token and the SOAP request.

More information:

Supported Authentication Schemes for Producing Each WS-Security Header Type