Brian Maso's Tecno-Geek WeblogThe musings of a mild-mannered tecno-geek.Credential Management- October 8, 2003 Sharing a few thoughts on security credential management that occurred to me this week... This issue is credential security: When a credential is presented to a system for authentication, how "assurred" is the system that the credential has not been compromised That the entity presenting the credential is actually an agent of the identity assocaited with the credential To assess "assurrance", you must first consider the type of credential. Token credentials, such as HTTP Session cookies or SAML.http://www.blumenfeld-maso.com/weblog/2003/10/08.html#a43 |