Next in thread → Next in month →

RE: [security-services] Proposal: Query Extension for SAML AuthnReq

From
Scott Cantor <>
Date
2008-05-05T19:59:17+00:00
ID
075e01c8aeea$7d5d35a0$7817a0e0$@
Thread
RE: [security-services] Proposal: Query Extension for SAML AuthnReq
> The existing inability of an SP to ask for particular 'assurance
> attributes' in its <AuthnRequest> would presumably be one driver for
> them to instead use <RequestedAuthnContext>?

Nope, because LOA-centric apps are almost always amenable to setting up the
attribute release out of band. It's all about who has to make changes when
the LOA set changes. Asserting multiple values is seen as a big deal.

I think I covered this on the Concordia list fairly well. Far from a kludge,
I think it's probably the long term approach most will eventually take
because it's a lot easier than asserting multiple context classes, not to
mention as Tom said, it works across protocols much more cleanly.

-- Scott
Next in thread → Next in month →