Exposing supported AuthnContextClasses in IdP Metadata
Scott Cantor
scott at restingparrotsoftware.com
Fri Jun 26 15:03:48 UTC 2026
> The main intended usage is metadata filtering at discovery and SP level, to target only MFA-capable IdPs.
Except "capable" does not mean "it will happen", and the usual use of such a tag is to give SPs cover to skip doing error handling, and that will never work.
So it's a use case that has hidden traps that most people wanting to do it don't tend to fully understand.
REFEDS has toyed with defining something, but it's never gone that far for good reasons. Also, as Peter said, who's going to see it? What else but Shibboleth really uses metadata extensions?
As far as how, nobody should be defining new extensions in 2026. Entity Attributes are the proper mechanism. We don't live in a world where people are willing or able to process XML flexibly enough to make new extensions work well.
-- Scott
More information about the users
mailing list