AuthnContextClassRef - Password vs PasswordProtectedTransport
Donald Lohr
lohrda at jmu.edu
Thu Jul 28 13:58:22 UTC 2022
Using the SAML tracer plugin for Firefox, on the SAML/POST entry after
successfully providing my credentials (SSO login to an SP) I see:
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:*PasswordProtectedTransport*</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
For some SP logins I see:
<saml2:AuthnContextClassRef>urn:oasis:names:tc:SAML:2.0:ac:classes:*Password*</saml2:AuthnContextClassRef>
</saml2:AuthnContext>
All I've been able to find thus far as an explanation is the following:
The *Password* class is applicable when a principal authenticates to an
authentication authority through the presentation of a password over an
unprotected HTTP session.
The *PasswordProtectedTransport* class is applicable when a principal
authenticates to an authentication authority through the presentation of
a password over a protected session.
Is *Password* or *PasswordProtectedTransport* controlled by how the SP
is configured on the IdP side?*
*
Thanks,
Don
--
D o n a l d L o h r
I n f o r m a t i o n S y s t e m s
J a m e s M a d i s o n U n i v e r s i t y
5 4 0 . 5 6 8 . 3 7 3 0
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220728/91a71605/attachment.htm>
More information about the users
mailing list