use of Scoping element in AuthnRequest to assist with front-channel attribute aggregation
Cantor, Scott
cantor.2 at osu.edu
Mon Nov 25 12:47:30 EST 2013
On 11/25/13, 11:52 AM, "Scott Koranda" <skoranda at gmail.com> wrote:
>Hello,
>
>If this is not an appropriate question for this list I would be
>grateful if you could point me to the correct list.
saml-dev at OASIS, I would suggest.
>I have come across some work on so-called "front-channel attribute
>aggregation" that is using a <Scoping> element as part of an
><AuthnRequest> element to include the entityID of an IdP already used
>to authenticate the subject. The entityID for the IdP is included in
>an <IDPList> element.
That's not what Scoping is for, definitely not.
>1) Is there any defined profile that addresses this type of
>front-channel attribute query or aggregation?
Not from OASIS.
>2) Any comments on the use of an <AuthnRequest> to the attribute
>authority to solicit attributes about the subject?
I don't think there is any separation of authentication here. From the SP
point of view, it's just authentication to another IdP, so that part is
fine.
>3) Any comments on the use of the <Scoping> element to signal to the
>attribute authority to which IdP to direct the browser to complete the
>assertion of a name identifier from the IdP to the attribute
>authority?
Inappropriate IMHO.
-- Scott
More information about the dev
mailing list