Previous Topic: How SAML Token Multistep Authentication, Holder-of-Key Works

Next Topic: How Chain Authentication Service Model, Sender-Vouches with Signature-Based Issuer Validation Works

How SAML Token Multistep Authentication, Sender-Vouches Works

This model does not require the assertion subject’s public and private keys bound to the SOAP document. The web service consumer’s public key is not supplied (by the web service consumer or the Policy Server) with a request. Upon validation of the request, the authentication service vouches for the web service consumer by generating a SAML token and binding it to the message body by signing them both with its private key using the sender-vouches subject confirmation method.

More information:

Supported Authentication Schemes for Producing Each WS-Security Header Type