AuthnContextClassRef - Password vs PasswordProtectedTransport

Donald Lohr lohrda at jmu.edu
Thu Jul 28 13:58:22 UTC 2022


Using the SAML tracer plugin for Firefox, on the SAML/POST entry after 
successfully providing my credentials (SSO login to an SP) I see:

<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:*PasswordProtectedTransport*</saml2:AuthnContextClassRef> 
</saml2:AuthnContext>

For some SP logins I see:

<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:*Password*</saml2:AuthnContextClassRef> 
</saml2:AuthnContext>

All I've been able to find thus far as an explanation is the following:

The *Password* class is applicable when a principal authenticates to an 
authentication authority through the presentation of a password over an 
unprotected HTTP session.

The *PasswordProtectedTransport* class is applicable when a principal 
authenticates to an authentication authority through the presentation of 
a password over a protected session.

Is *Password* or *PasswordProtectedTransport* controlled by how the SP 
is configured on the IdP side?*
*
Thanks,
Don

-- 
D o n a l d   L o h r
I n f o r m a t i o n   S y s t e m s
J a m e s   M a d i s o n   U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220728/91a71605/attachment.htm>


More information about the users mailing list