Exposing supported AuthnContextClasses in IdP Metadata

Scott Cantor scott at restingparrotsoftware.com
Fri Sep 18 15:16:19 UTC 2026


> The SFA/MFA specs only define these URIs as part of protocol messages
> (authn requests, returned assertions/claims), *not* within SAML
> metadata. I..e, use of these MFA/SFA URIs in the context of Entity
> Attributes is fully undefined. I.e., you'd be making up your own
> semantics using someone else's identifiers. Don't do that.

We did discuss it and we knew people wanted it. The reasons we held back (again) are partly in my earlier email.

The semantics of advertising this in metadata are a lot more subtle than people tend to think they are, and they're particularly messy from the RP side, which is also something people have asked for.

The IdP side is somewhat clearer as to what it would *probably* mean, but there the problem is, as I said, that it doesn't actually mean what a lot of people seem to assume it would, and it's not at all clear that the imprecision wouldn't create more problems than it solves.

The WG's decision was to tell REFEDS steering "if you want this, a new WG needs to be convened to dicuss it and get it *right*" rather than us just doing something with no real input into requirements beyond a lot of hand waving.

I'm not trying to speak for the rest of the WG but I hope that's a reasonable accurate summary of the views.

-- Scott



More information about the users mailing list