> > The SAML specs use the phrase "at least one authentication
statement"
> > in various places, which leaves open the possibility of multiple
such
> > statements. When might an assertion have multiple authentication
> > statements? Is there a use case for that?
>
> None I could ever come up with. I wanted the SSO profile to require
only
> one, biggest annoyance implementing it IMHO.
I wonder if this is part of the per-statement subject legacy where
you could have different Authn statements that applied to different
subjects and the one that would apply in any particular context
would be the one who's subject was confirmed.
Conor