separating AuthenticationMethod contexts
Tom Scavo
trscavo at gmail.com
Tue Jun 12 15:22:57 BST 2012
On Tue, Jun 12, 2012 at 9:57 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 6/12/12 8:10 AM, "Tom Scavo" <trscavo at gmail.com> wrote:
>>
>>Thanks for the clarification. What if there are multiple
>><saml:AuthnContextClassRef> elements in the request? SAML2 Core
>>clearly says the ordering is significant but it doesn't really specify
>>how the IdP honors that ordering. What does the IdP do in this case?
>
> If PreviousSession is enabled, it favors SSO by picking the first active
> matching method, and then falls back to choosing an inactive method if
> none are active.
Seems like a reasonable strategy (although completely undocumented).
Is that what the current Shib IdP does, or are you saying that's what
it should/will do?
Thanks,
Tom
More information about the users
mailing list