ISSUE[UC-1-01:Shibboleth]
1. The above list of issues, combined with the straw man 2 document, address the requirements of Shibboleth, and no further investigation of Shibboleth is necessary. Close this issue.
2. Additional investigation of Shibboleth requirements are needed.
ISSUE[UC-1-02:ThirdParty]
1. Edit the current third-party use case scenario to feature passing a third-party authentication assertion from one destination site to another.
2. Remove the third-party use case scenario entirely.
ISSUE[UC-1-03:ThirdPartyDoable]
1. The use case scenario should be removed because it is not ‘implementable’.
2. The use case scenario is ‘implementable’, and whether it should stay in the document or not should be decided based on other factors.
ISSUE[UC-1-04:ARundgrenPush]
1. Use this variation to replace scenario 2 in the use case document.
2. Add this variation as an additional scenario in the use case document.
3. Do not add this use case scenario to the use case document.
ISSUE[UC-1-05:FirstContact]
1. Add this use case scenario to the use case document.
2. Do not add this use case scenario to the use case document.
ISSUE[UC-1-06:Anonymity]
1. Add this requirement to the use case and requirement document.
2. Do not add this requirement.
ISSUE[UC-1-07:Pseudonymity]
1. Add this requirement to the use case and requirement document.
2. Do not add this requirement.
ISSUE[UC-1-08:AuthZAttrs]
1. Edit the use case scenarios to specify passing authz attributes with authentication documents for the SSO scenarios.
2. Do not specify the passing of authz attributes in the use case scenarios.
ISSUE[UC-1-09:AuthZDecisions]
1. Edit the use case scenarios to use the term "authz decision" and add the [R-AuthZDecision] requirement.
2. Do not make these changes.
ISSUE[UC-1-10:UnknownParty]
1. Add this use case scenario to the use case document.
2. Do not add this use case scenario to the use case document.
ISSUE[UC-1-11:AuthCEvents]
1. Edit the use case scenarios to specifically define when authc event descriptions are transferred, and edit the R-AuthC requirement.
2. Do not change the use case scenarios or R-AuthC requirement.