MCB and default authn context for an SP/RP in relying-party

Michael A Grady mgrady at unicon.net
Thu Mar 5 20:40:08 EST 2015


On Mar 5, 2015, at 4:34 PM, Paul Hethmon <paul.hethmon at clareitysecurity.com> wrote:

> 
>> On Mar 5, 2015, at 5:26 PM, Michael A Grady <mgrady at unicon.net> wrote:
>> 
>> If I'm reading the following correctly:
>> 
>> https://github.com/Internet2/Shibboleth-Multi-Context-Broker/issues/11
>> 
>> it would appear that as of 1.2.1 (now at 1.2.2), the MCB added support for using the  default authn context for an SP/RP in the IdP's relying-party config file. Is that correct, and if so, in what situations? Only if the SP does not specify a context, or does this override/take precedence for that SP?
> 
> 
> It’s only used if the SP does not send a value.

Thanks for that. That's something, although personally, I think it should have overridden any value the SP sent, although I understand the debate around that. (I would have at least have it override if the requested context was any form of the password-only based contexts.)


> 
> Paul
> 
> -----
> Paul Hethmon
> Chief Software Architect
> paul.hethmon at clareitysecurity.com

--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.



More information about the users mailing list