Exposing supported AuthnContextClasses in IdP Metadata
Peter Schober
peter.schober at univie.ac.at
Fri Jun 26 12:52:24 UTC 2026
Guillaume Rousse via users <users at shibboleth.net> [2026-06-26 14:04 CEST]:
> I'm currently hesitating between two options:
> - a multivalued entity attribute
> - a dedicated metadata extension
You may be missing a third one:
https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-assurance-profile.html
> The first one seems the easiest to achieve (no additional schema needed) A
> dedicated metadata extension would however provide a better visibility, but
> may have unwanted impact on other SAML implementation.
"Better visibility" in what way, exactly -- are you assuming people
are eyeballing your XML? Or in the sense of the latter argument, that
(potential) breakage would provide additional exposure? ;)
FWIW, in the rights spot (lax validation) extensions shouldn't break
anything, not evel lesser implementations. If they did you'd know by
now, I suppose, given all the extensions we routinely use.
(That should not be taken as an argument in favor of creating your own
extension, though.)
Best,
-peter
More information about the users
mailing list