<div dir="ltr"><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Feb 6, 2017 at 4:39 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div id=":db1" class="a3s aXjCH m15a1595b51ea066c">If your flow supports a custom AuthnContextClassPrincipal called "urn:foo" then put urn:foo in the header and it will include that in the Subject. That's pretty much it.<br></div></blockquote></div><br>Couldn't someone insert an illicit header on the browser side?</div><div class="gmail_extra"><br></div><div class="gmail_extra">Liam</div></div>