Can Shib IDP include multiple AuthnContextClassRef elements in the SAML response?

Cantor, Scott cantor.2 at osu.edu
Fri Feb 5 09:06:06 EST 2016


> I am working on a requirement supporting a MFA case using Shibboleth IDP
> where the relying party wants IDP to include all the authentication methods
> in the multiple AuthnContextClassRef elements such as:

That isn't allowed, so no, it's not possible for the IdP to do it.

-- Scott



More information about the dev mailing list