<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">The Shibboleth SP supports the other operators via authnContextComparison.<br></blockquote><div><br></div><div>Yeah, I just realized that. (SAML ignorance was the root problem.) Adding the following directive to the SP gets my IdP configuration working like I had expected:</div><div><br></div><div>ShibRequestSetting authnContextComparison better</div><div><br></div><div>This leads to a new question: is it common for SPs to specify custom matching semantics when specifying a required authn context class?</div><div><br></div><div>Thanks,</div><div>M<a href="mailto:users-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>