use of Scoping element in AuthnRequest to assist with front-channel attribute aggregation

Cantor, Scott cantor.2 at osu.edu
Mon Nov 25 12:47:30 EST 2013


On 11/25/13, 11:52 AM, "Scott Koranda" <skoranda at gmail.com> wrote:

>Hello,
>
>If this is not an appropriate question for this list I would be
>grateful if you could point me to the correct list.

saml-dev at OASIS, I would suggest.


>I have come across some work on so-called "front-channel attribute
>aggregation" that is using a <Scoping> element as part of an
><AuthnRequest> element to include the entityID of an IdP already used
>to authenticate the subject. The entityID for the IdP is included in
>an <IDPList> element.

That's not what Scoping is for, definitely not.

>1) Is there any defined profile that addresses this type of
>front-channel attribute query or aggregation?

Not from OASIS.

>2) Any comments on the use of an <AuthnRequest> to the attribute
>authority to solicit attributes about the subject?

I don't think there is any separation of authentication here. From the SP
point of view, it's just authentication to another IdP, so that part is
fine.

>3) Any comments on the use of the <Scoping> element to signal to the
>attribute authority to which IdP to direct the browser to complete the
>assertion of a name identifier from the IdP to the attribute
>authority?

Inappropriate IMHO.

-- Scott




More information about the dev mailing list