Can Shib IDP include multiple AuthnContextClassRef elements in the SAML response?

Joey Wang carbon_60 at yahoo.com
Fri Feb 5 12:22:08 EST 2016


Thanks, Scott,
According to Saml-core-2.0 doc (see below), it is optional for IDP to include all matching assertions in the response. Are you saying Shib 3.2.x currently does not support this option and there is no way we can extend it (without modifying the core of Shib IDP) to support this option?
Thanks, Joey
<RequestedAuthnContext>[Optional]If present,specifies a filter for possible responses. Such a query asks the question"What assertionscontainingauthentication statements do you have for this subject that satisfy theauthenticationcontext requirementsin this element?"In response to anauthentication query, a SAML authority returns assertions with authenticationstatements asfollows:• If the<RequestedAuthnContext> element is present in the query, at least one<AuthnStatement>element in the set of returned assertions MUST contain an<AuthnContext>element that satisfies the element in the query (see Section 3.3.2.2.1). It isOPTIONAL for the complete set ofall such matching assertions to be returned in the response.
 

    On Friday, February 5, 2016 9:06 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
 

 > I am working on a requirement supporting a MFA case using Shibboleth IDP
> where the relying party wants IDP to include all the authentication methods
> in the multiple AuthnContextClassRef elements such as:

That isn't allowed, so no, it's not possible for the IdP to do it.

-- Scott

-- 
To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


  
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20160205/5da9d3cb/attachment.html>


More information about the dev mailing list