[JIRA] Created: (IDP-155) Options for RequestedAuthnContext spec strictness
Scott Cantor (JIRA)
noreply at shibboleth.net
Mon Feb 27 16:04:38 GMT 2012
Options for RequestedAuthnContext spec strictness
-------------------------------------------------
Key: IDP-155
URL: https://issues.shibboleth.net/jira/browse/IDP-155
Project: Identity Provider
Issue Type: Improvement
Components: Authentication
Reporter: Scott Cantor
Assignee: Chad La Joie
Priority: Minor
The assurance related testing that's been going on with V2 has identitied a couple of areas where the spec is gray enough to lead to non-interoperable behavior. In most respects, the things the V2 IdP does make "sense":
- treating "unspecified" as a wildcard rather than an exact match
- favoring authentication methods associated with the session rather than walking the order specified in the request
The latter in particular seems to appeal to people since it improves SSO, but technically the spec makes the ordering in the request normative.
I think it would be helpful long term for interop to support some options that influence the "strictness" of the behavior and allow for some flexibility in how closely it follows the letter of the spec.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list