saml2 authentication contexts

Cantor, Scott cantor.2 at osu.edu
Wed Sep 25 17:40:52 EDT 2013


On 9/25/13 5:33 PM, "Tom Scavo" <trscavo at gmail.com> wrote:

>Liam, let me add that the AuthnContext URIs specified above aren't
>very useful in real world deployments. Every use of AuthnContext I've
>seen involved a custom URI with a well-understand semantic. (Well
>understood by its intended users of course.)

The non-esoteric ones are mostly fine, lots of campuses are using things
like TimeSyncToken to handle two-factor (we are for one), and I know from
the TC calls that the vendors have definitely used them in customer
deployments.

I wouldn't vouch for any of the weirder ones meaning much though.

-- Scott




More information about the users mailing list