Re: [saml-dev] Confusion regarding AuthnContext

From
Som Rcavo
Date
2009-09-20T16:04:44+00:00
ID
Thread
Re: [saml-dev] Confusion regarding AuthnContext
On Sat, Sep 19, 2009 at 8:16 PM, bhaskar jain
<> wrote:
>
> Is it a violation of the SAML standards, when you authenticate using a less
> secure method and claim to have done using  a 'strong' method.

I should think the answer to this question is obvious. If what you (as
an IdP) assert in the authentication response is false, then clearly
there is no basis for trust whatsoever.

Tom