Skip to Content.
Sympa Menu

mfa-interop - RE: [MFA-Interop] Software support for our MFA Interoperability authnContext value

Subject: MFA Interop Working Group

List archive

RE: [MFA-Interop] Software support for our MFA Interoperability authnContext value


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: Nicholas Roy <>, "" <>
  • Subject: RE: [MFA-Interop] Software support for our MFA Interoperability authnContext value
  • Date: Fri, 7 Oct 2016 20:06:13 +0000
  • Accept-language: en-US
  • Authentication-results: spf=pass (sender IP is 164.107.81.208) smtp.mailfrom=osu.edu; incommon.org; dkim=none (message not signed) header.d=none;incommon.org; dmarc=bestguesspass action=none header.from=osu.edu;
  • Ironport-phdr: 9a23:HVBZCB+Qk1D22f9uRHKM819IXTAuvvDOBiVQ1KB91uscTK2v8tzYMVDF4r011RmSAtWdtqkP0reempujcFJDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBX660e/5j8KGxj5KRE9ZqGsQtaT3IyL0LWU+pbTZAFBn3KHZqI6eBOsqhT5t88KjJFkJ7prjBbFvy0MM65Ty2otJFSPkgz7/u+x+pVk9iFXvbQm7cEKGfH/ca19TLpEAS4hK0g04sbssBzES02I/HRKAUsMlR8dSSPM6g39RNO5iSD9qvY3kH2RNMvqSqpyAxyl9LotRRP13nRUfwUl+X3a35QjxJlQpwis8lkmm9bZ
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

> Seems like this is something that SSP should support if it doesn't, and
> I don't think that missing it should block adoption of this profile.
> The profile should drive software that doesn't support it, to support it.

This is basic SAML conformance stuff, but I think Eric more or less asked
just yesterday that the implementation profile go ahead and include explicit
requirements for this to call it out. There's also a more important and
generally overlooked piece, which is that if the SP requests it, it needs to
be able to enforce it (and if not, the application had better know that it
hasn't been enforced). That could be added to the implementation profile as
well.

-- Scott





Archive powered by MHonArc 2.6.19.

Top of Page