Protocol Deprecation (Was: Deprecation of SAML2NameID attribute ...)

John Dennis jdennis at redhat.com
Fri Apr 17 12:59:02 EDT 2015


On 04/17/2015 10:32 AM, Cantor, Scott wrote:
> I considered that a deprecated feature because there
> has never been a good reason to pass it as an attribute in SAML 2,
> only SAML 1. Since all of SAML 1 is sort of deprecated in a general
> sense, I didn't plug that gap (and it was essentially impossible to
> do, they're totally separate features).

Speaking of SAML v1 being deprecated I have some general deprecation
questions. My understanding is Liberty ID-FF also deprecated and
superseded by SAML v2. Correct?

Is there any significant deployments in the field which still rely on
either SAML v1 or Liberty ID-FF? I ask because I'm working with some
code that supports SAML v1 and ID-FF in addition to SAML2. Supporting
these in addition to SAML v2 makes the code much more complex and
appears to me to just be cruft that could be cleaned up. In 2015 is
there any reason to continue to support these other protocols?

-- 
John


More information about the users mailing list