Re: [security-services] comments re sstc-saml-holder-of-key-browser-sso-draft-10
In the HoK Web Browser SSO Profile, what bindings MUST the IdP and the SP support for conformance purposes? I would think that the SP MUST support HTTP Redirect while the IdP MUST support HTTP POST. Does this sound reasonable? Tom