← Prev in month ← Prev in thread

AuthnRequest Subject vs. NameIDPolicy usage

From
Thomas Wisniewski <>
Date
2005-06-03T12:11:55+00:00
ID
Thread
AuthnRequest Subject vs. NameIDPolicy usage
Title: Message

All, I'm trying to 
understand Profiles section 4.1.4.1 (<AuthnRequest> 
Usage). Specifically the fact that Subject is allowed and how this related to 
NameIDPolicy.  I assume the reason Subject is allowed is to because 
the requesting service provider may know the subject's identity and 
wants the identity provider to match this against the user being authenticated. 
It would seem that this should imply that NameIDPolicy's Format and 
SPNameQualifier attributes MUST be omitted in this case. 
The AllowCreate attribute could be used as it currently is. Is that the 
intent? If not and both are used such that the Format and/or 
SPNameQualifier attributes are defined in both (and of course possibily 
different), what would be the processing rules?

 

I'm proposing that 
these two attributes in NameIDPolicy not be used when using 
Subject.

 

Tom.

Thomas Wisniewski
Software Architect 
Phone: (201) 
891-0524 
Cell: (201) 248-3668 

  
EntrustÒ 
Securing Digital Identities
& Information
← Prev in month ← Prev in thread