|
Consensus Item Name: Acceptance of RequestedAuthnContext
Test Event: SAML Interoperability Test Event 3Q08
Consensus Decision: In an authentication request message, an interoperable implementation must accept a RequestedAuthnContext if it can meet the authentication context requirements of the specified element and not require that such information be specified out-of-band.
Background: One implementation originally rejected AuthnRequest messages if they contained the optional RequestedAuthnContext field under the belief that it was not necessary as the same information could be exchanged out-of-band. After consulting with Liberty TEG, it was decided that it must be accepted and processed per the SAML specifications regardless of what was exchanged out-of-band.
|