OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

saml-dev message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: [saml-dev] the value of AuthnInstant



> 
> A bearer token is a form of authentication, and a cookie is a 
> bearer token.
> But if an IdP decides to implement itself without retaining 
> enough state to
> remember the original time, it's not compliant?
> 

I would say that if an IdP does not retain enough state to produce an AuthnStatement that is internally consistent (i.e., all the content describes the same authentication event) then, in fact, it's not compliant. Thus, if an IdP does not preserve the time that the user presented his password, it cannot claim Password AC after the first AuthnStatement, and must henceforth use ExistingSession as the AC.

::Ari



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]