separating AuthenticationMethod contexts

Chad La Joie lajoie at itumi.biz
Mon Jun 11 15:10:06 BST 2012


Well, currently, it's working as intended. The default method was
designed only as an input to the process of selecting the authn method
to use when it was decided authentication was required.

We could certainly have a discussion whether some other behavior is
needed.  As a starting point I'll note that this is one of the
settings that the SAML spec allows the SP to mandate.  In such cases
the IdP does not provide settings that mandate particular things in
order to prevent cases where the SP mandate and the IdP mandage
conflict.  In other words, such IdP settings are only hints of what
should be done when the SP doesn't mandate something.

On Mon, Jun 11, 2012 at 9:58 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/8/12 7:02 PM, "Russell Beall" <beall at usc.edu> wrote:
>>
>>It seems that when an SP does not request a particular authentication
>>context, the IdP will use an existing one that is active, even if it is
>>not specified as the default for the relying party in the
>>relying-party.xml file.
>
> I think that's true, yes. That's arguably a bug, or at least something
> fairly subtle to document.

-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the users mailing list