Error in MFA with disallowed AUTHNCONTEXT + requested PasswordProtectedTransport
Cantor, Scott
cantor.2 at osu.edu
Sun Jul 2 10:51:01 EDT 2017
>> I have a SP that requires PasswordProtectedTransport. If we set
>> disallowedFeatures-ref="SAML2.SSO.FEATURE_AUTHNCONTEXT" in
>> relying-party.xml, per the wiki, we get an error:
>
> That's the purpose of the feature, that's what it does.
(By which I'm saying, its purpose is to prevent an SP from requesting something because you've chosen to define what it should get in your IdP configuration. The other option is to require signed requests so that only the SP itself can override the rule, which presumably it can't do since if it could request anything specific you wouldn't have configured this on the IdP side to begin with.)
-- Scott
More information about the users
mailing list