the saml2p:Scoping block in authn requests

Cantor, Scott cantor.2 at osu.edu
Wed Apr 4 17:23:20 EDT 2018


> > I didn't say I thought it was normal; it was just in the ECP excerpt
> > that we started with, and at this point, I can't remember where we even
> started.
> 
> I think the SP might include it because Scoping has an obscure ability to
> include the name of an IdP so a client UI could display it. In that scenario, it's
> not inside the AuthnRequest, it's in a SOAP header for the client to read.

Hmm, no, you're right. The SP does include that inside the request. I have no idea why, it was not well thought out and serves no purpose there. Sorry for the confusion.

-- Scott



More information about the dev mailing list