Tom,
Appreciate your response. I think it was coming but still do you know of any real-life SP's which restrict AuthnContextClass to a particular class and do not allow it to be configurable on the SP side?
Thanks.
--Bhaskar.
On Sun, Sep 20, 2009 at 9:34 PM, Tom Scavo <> wrote:
On Sat, Sep 19, 2009 at 8:16 PM, bhaskar jain
<> wrote:
>
> Is it a violation of the SAML standards, when you authenticate using a less
> secure method and claim to have done using a 'strong' method.
I should think the answer to this question is obvious. If what you (as
an IdP) assert in the authentication response is false, then clearly
there is no basis for trust whatsoever.
Tom