I would agree. In practice and potentially in an interop, only HTTP Redirect
would impose unnecessary, but required, limitations to how a request is
formed.
Tom.
-----Original Message-----
From: Scott Cantor [mailto:]
Sent: Tuesday, October 26, 2004 6:24 PM
To: 'Thomas Wisniewski'
Cc:
Subject: RE: [security-services] Web SSO <AuthnRequest> conformance
> Seems reasonable. Do you feel it will be added to the conf
> spec as MUST?
I'd be in favor of making POST MTI, and I think we have to do something.
The ability to do artifact was mostly just a consequence of layering the
spec the way I did (i.e. you get it for free architecturally), but there
wasn't overwhelming interest in using it for anything else.
-- Scott