separating AuthenticationMethod contexts
Tom Scavo
trscavo at gmail.com
Tue Jun 12 13:10:14 BST 2012
On Mon, Jun 11, 2012 at 10:30 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/11/12 10:10 AM, "Chad La Joie" <lajoie at itumi.biz> wrote:
>
>>Well, currently, it's working as intended. The default method was
>>designed only as an input to the process of selecting the authn method
>>to use when it was decided authentication was required.
>
> I'm working on improving the docs a bit, but I also think the last couple
> of paragraphs in the method selection doc are wrong. They kind of imply
> exactly the behavior that it isn't manifesting, so we'll work on it.
Thanks for the clarification. What if there are multiple
<saml:AuthnContextClassRef> elements in the request? SAML2 Core
clearly says the ordering is significant but it doesn't really specify
how the IdP honors that ordering. What does the IdP do in this case?
Thanks,
Tom
More information about the users
mailing list