Exposing supported AuthnContextClasses in IdP Metadata

Guillaume Rousse guillaume.rousse at renater.fr
Fri Jun 26 12:04:02 UTC 2026


Hello list.

We'd like to make IdPs able to expose supported AuthnContextClasses in 
their metadata, the same way they are already able to expose supported 
NamedID formats (<NameIDFormat>), supported attributes 
(<saml:Attribute>), ... Unless I'm wrong, there seems to be no such 
element already suitable for this usage.

I'm currently hesitating between two options:
- a multivalued entity attribute
- a dedicated metadata extension

The first one seems the easiest to achieve (no additional schema needed) 
A dedicated metadata extension would however provide a better 
visibility, but may have unwanted impact on  other SAML implementation.

The main intended usage is metadata filtering at discovery and SP level, 
to target only MFA-capable IdPs.

Regards.
-- 
Guillaume Rousse
Direction des Services Applicatifs
RENATER - Paris

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4291 bytes
Desc: Signature cryptographique S/MIME
URL: <http://shibboleth.net/pipermail/users/attachments/20260626/bb179874/attachment.p7s>


More information about the users mailing list