[ https://issues.apache.org/jira/browse/CXF-3940?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13159268#comment-13159268 ]
Jan Bernhardt commented on CXF-3940: ------------------------------------ Hi Colm, I was only looking at the 2.5.0 code. I assumed the patch would only contain SAML Attribute Handling... I was just in contact with Oliver how pointed out, that this patch also modifies the DefaultSubjectProvider. I will have to check this out. But my issue is probably already solved... Thanks. Jan > A SAML Token requested OnBehalfOf should hide the actual requestor and should > only contain the OnBehalfOf Identity > ------------------------------------------------------------------------------------------------------------------ > > Key: CXF-3940 > URL: https://issues.apache.org/jira/browse/CXF-3940 > Project: CXF > Issue Type: Sub-task > Components: Services > Affects Versions: 2.5 > Reporter: Jan Bernhardt > Labels: SAML, WS-Trust, sts > Fix For: 2.5.1 > > Original Estimate: 48h > Remaining Estimate: 48h > > As far as I know, to request an OnBehalfOf Token should not simply result in > adding a related SAML Attribute (as it would be ok for ActAs). OnBehalfOf > should deliver a Token where "only" the OnBehalfOf Principal is contained. > Therefor the SAML Subject should match the requested OnBehalfOf Principal and > not the Principal which was authenticated based on the security token sent in > the WS-Security header... -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa For more information on JIRA, see: http://www.atlassian.com/software/jira