I am going to guess that what you are referring to is Section 4 of the
SAML Profile.
The SAML-based policy request profile was never intended to be used for
provisioning. Its purpose was to allow a server to provide polices on a
per-request basis to a PDP with little or no non-volatile storage. It
provides no means to distribute a subset of available policies without
duplicates.
As I have said repeatedly, I think the case of transferring ALL polices
can be easily covered using existing protocols, e.g. ftp. However, my
proposed design does permit the transfer of any subset, including all
policies.
Your question does raise some other points. Should the policies and
policy sets be delivered "naked" or wrapped in a SAML assertion? My
thinking was that these polices had already be vetted by a trusted PAP
and therefore it would be simpler and more efficient to send them
without a SAML wrapper. Message protection, if desired can be provided
by TLS or WS-Security as specified elsewhere. As a result of these
considerations I was not even planning to make this a part of the SAML
Profile, but a new free standing Profile.
So the short answer is that these are new protocols with different
functionality from the current policy query protocol.
Hal