ForceAuthn="true" vs ForceAuthn="1"

Robert Lowe robertmlowe at rmlowe.com
Wed Nov 29 13:26:14 EST 2017


> > I'm well aware that under W3C Schema these ought to be equivalent. I
> guess they are reading the specification rather literally.
>
> No, they're reading it wrongly.
>

They are pointing at page 49 of this document
<https://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf>,
which says (lines 2043-2046):

“A Boolean value. If "true", the identity provider MUST authenticate the
presenter directly rather than rely on a previous security context.”

To be fair it's not hard to see that that could be read as implying that
the value must literally be "true".

Was that clarified in an errata somewhere?

-- 
Best regards,

Robert Lowe
http://crepuscular.rmlowe.com/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171130/ef11a32f/attachment-0001.html>


More information about the users mailing list