Skip to Content.
Sympa Menu

shibboleth-dev - Re: authentication strength

Subject: Shibboleth Developers

List archive

Re: authentication strength


Chronological Thread 
  • From: Walter Hoehn <>
  • To:
  • Subject: Re: authentication strength
  • Date: Wed, 15 Feb 2006 12:58:21 -0600

On Feb 15, 2006, at 10:21 AM, Tom Scavo wrote:

1. Document HTTP header SAMLAuthenticationMethod in the Shib 1.3
deployment guides.

Sounds reasonable. The options are dead simple. You can add this to the wiki yourself, or I'll do it if you put in a bugzilla.

2. Either profile the use of the AuthenticationMethod attribute in the
Shibboleth profiles or map the SAML 1.1 values to LOA at the
federation level.

I'm not sure I understand what we would profile in Shibboleth. The authN method stuff is already in the SAML 1.1 spec. With respect to level's of assurance, authentication method is only one of many inputs into any LOA algorithm.

-Walter




Archive powered by MHonArc 2.6.16.

Top of Page