Exposing supported AuthnContextClasses in IdP Metadata
Scott Cantor
scott at restingparrotsoftware.com
Fri Sep 18 14:25:59 UTC 2026
> As federation operators, we are trying to provide visibility in our community, so as to reduce the chicken-and-egg issue: in order to convince SP admins they can begin using explicit AuthnContext requirements in their SAML requests, we have to convince them a reasonable part of our community will be able to answer those requests.
Except that you can't really give them what they want, which is a license to not handle errors. Almost no IdP can say "I will always be able to respond successfully to a request for a particular context class."
They can say "I recognize it and will handle it with a defined meaning and return an error if I need to", but even there, the way MFA works is such that most of the time users can't even be ensured of being returned to the SP in the case of a problem.
So you have both the "I don't want to or can't handle errors" motive, and the "I need the user back and you're not promising me that" demand, and both end up disqualifying.
The community really needs to solve that larger set of federation expectation issues before a conversation around signaling gets you very far. People keep trying to solve the easy parts and not the hard parts, but we're out of easy problems for the most part.
(That's all more or less paraphrasing the discussions that took place multiple times amongst the REFEDS MFA working groups.)
-- Scott
More information about the users
mailing list