the saml2p:Scoping block in authn requests
Cantor, Scott
cantor.2 at osu.edu
Wed Apr 4 17:10:35 EDT 2018
> I didn't say I thought it was normal; it was just in the ECP excerpt that we
> started with, and at this point, I can't remember where we even started.
I think the SP might include it because Scoping has an obscure ability to include the name of an IdP so a client UI could display it. In that scenario, it's not inside the AuthnRequest, it's in a SOAP header for the client to read.
-- Scott
More information about the dev
mailing list