Thanks Scott, I'll admit to being in the 99.9% of the population that doesn't fully understand subject confirmation but aren't NotOnOrAfter and Recipient in SubjectConfirmationData also redundant AudienceRestriction/Audience and NotOnOrAfter Conditions?
On Wed, Jun 16, 2010 at 12:45 PM, Scott Cantor <> wrote:
> Can anyone explain the rational behind having the MUST NOT on the
NotBefore
> attribute of <SubjectConfirmationData> in the Web Browerser SSO profile
> (section 4.1.4.2 of saml-core-2.0-os)?
I think it was to avoid a value that would just be redundant to IssueInstant
or a Condition.
-- Scott