[JIRA] Created: (IDP-155) Options for RequestedAuthnContext spec strictness

Scott Cantor (JIRA) noreply at shibboleth.net
Mon Feb 27 16:04:38 GMT 2012


Options for RequestedAuthnContext spec strictness
-------------------------------------------------

                 Key: IDP-155
                 URL: https://issues.shibboleth.net/jira/browse/IDP-155
             Project: Identity Provider
          Issue Type: Improvement
          Components: Authentication
            Reporter: Scott Cantor
            Assignee: Chad La Joie
            Priority: Minor


The assurance related testing that's been going on with V2 has identitied a couple of areas where the spec is gray enough to lead to non-interoperable behavior. In most respects, the things the V2 IdP does make "sense":

- treating "unspecified" as a wildcard rather than an exact match
- favoring authentication methods associated with the session rather than walking the order specified in the request

The latter in particular seems to appeal to people since it improves SSO, but technically the spec makes the ordering in the request normative.

I think it would be helpful long term for interop to support some options that influence the "strictness" of the behavior and allow for some flexibility in how closely it follows the letter of the spec.

--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira


More information about the commits mailing list