<html><head></head><body><div style="color:#000; background-color:#fff; font-family:HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px"><div id="yui_3_16_0_1_1454676233632_23517">Thanks, Scott,</div><div id="yui_3_16_0_1_1454676233632_23515"><br></div><div id="yui_3_16_0_1_1454676233632_23519" dir="ltr">According to Saml-core-2.0 doc (see below), it is optional for IDP to include all matching assertions in the response. Are you saying Shib 3.2.x currently does not support this option and there is no way we can extend it (without modifying the core of Shib IDP) to support this option?</div><div id="yui_3_16_0_1_1454676233632_23736" dir="ltr"><br></div><div id="yui_3_16_0_1_1454676233632_23734" dir="ltr">Thanks, Joey</div><div id="yui_3_16_0_1_1454676233632_23732"><br></div><div id="yui_3_16_0_1_1454676233632_23782">
</div><div id="yui_3_16_0_1_1454676233632_23555" style="margin:0in;font-family:Calibri;font-size:11.0pt"><RequestedAuthnContext>
[Optional]</div><div id="yui_3_16_0_1_1454676233632_23557">
</div><div id="yui_3_16_0_1_1454676233632_23559" style="margin:0in;font-family:Calibri;font-size:11.0pt">If present,
specifies a filter for possible responses. Such a query asks the question
"What assertions</div><div id="yui_3_16_0_1_1454676233632_23561">
</div><div id="yui_3_16_0_1_1454676233632_23563" style="margin:0in;font-family:Calibri;font-size:11.0pt">containing
authentication statements do you have for this subject that satisfy the
authentication</div><div id="yui_3_16_0_1_1454676233632_23565">
</div><div id="yui_3_16_0_1_1454676233632_23567" style="margin:0in;font-family:Calibri;font-size:11.0pt">context requirements
in this element?"</div><div id="yui_3_16_0_1_1454676233632_23569">
</div><div id="yui_3_16_0_1_1454676233632_23571" style="margin:0in;font-family:Calibri;font-size:11.0pt">In response to an
authentication query, a SAML authority returns assertions with authentication</div><div id="yui_3_16_0_1_1454676233632_23573">
</div><div id="yui_3_16_0_1_1454676233632_23575" style="margin:0in;font-family:Calibri;font-size:11.0pt">statements as
follows:</div><div id="yui_3_16_0_1_1454676233632_23577">
</div><div id="yui_3_16_0_1_1454676233632_23579" style="margin:0in;font-family:Calibri;font-size:11.0pt">• If the
<RequestedAuthnContext> element is present in the query, at least one</div><div id="yui_3_16_0_1_1454676233632_23581">
</div><div id="yui_3_16_0_1_1454676233632_23583" style="margin:0in;font-family:Calibri;font-size:11.0pt"><AuthnStatement>
element in the set of returned assertions MUST contain an</div><div id="yui_3_16_0_1_1454676233632_23585">
</div><div id="yui_3_16_0_1_1454676233632_23587" style="margin:0in;font-family:Calibri;font-size:11.0pt"><AuthnContext>
element that satisfies the element in the query (see Section 3.3.2.2.1). <span id="yui_3_16_0_1_1454676233632_23589" style="background:yellow;mso-highlight:yellow">It is</span></div><div id="yui_3_16_0_1_1454676233632_23591">
</div><div id="yui_3_16_0_1_1454676233632_23593" style="margin:0in;font-family:Calibri;font-size:11.0pt"><span id="yui_3_16_0_1_1454676233632_23595" style="background:yellow;mso-highlight:yellow">OPTIONAL for the complete set of
all such matching assertions to be returned in the response</span>.</div><div id="yui_3_16_0_1_1454676233632_23597" dir="ltr">
</div><div dir="ltr"><br></div> <div class="qtdSeparateBR"><br><br></div><div class="yahoo_quoted" style="display: block;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;"> <div dir="ltr"><font face="Arial" size="2"> On Friday, February 5, 2016 9:06 AM, "Cantor, Scott" <cantor.2@osu.edu> wrote:<br></font></div> <br><br> <div class="y_msg_container"><div class="yqt4215240585" id="yqtfd61038">> I am working on a requirement supporting a MFA case using Shibboleth IDP<br clear="none">> where the relying party wants IDP to include all the authentication methods<br clear="none">> in the multiple AuthnContextClassRef elements such as:</div><br clear="none"><br clear="none">That isn't allowed, so no, it's not possible for the IdP to do it.<br clear="none"><br clear="none">-- Scott<br clear="none"><br clear="none">-- <br clear="none">To unsubscribe from this list send an email to <a class="removed-link" href="" shape="rect" ymailto="mailto:dev-unsubscribe@shibboleth.net">dev-unsubscribe@shibboleth.net</a><div class="yqt4215240585" id="yqtfd63809"><br clear="none"></div><br><br></div> </div> </div> </div></div></body></html>