> There's the rub. The IdPs I have in mind don't support SAML protocol
> messages, they simply issue assertions. The protocols and bindings
> used to transmit the assertions to SPs are totally outside the SAML
> specification.
That's true of WS-Federation too, but it didn't stop me from profiling
IDPSSODescriptor for it a couple of years back, and I don't think that was
the wrong decision.
I think there will be lots of metadata specs and it would be a mistake to
get too hung up on the meaning unless there's a concern over the effects on
implementations. As long as those concerns are taken into account, anything
goes.
-- Scott