SAML 2.0: LECP Solution Proposal
Work Plan Item W-5a
SAML 2.0: LECP Solution Proposal Work Plan Item W-5a Frederick - - PowerPoint PPT Presentation
SAML 2.0: LECP Solution Proposal Work Plan Item W-5a Frederick Hirsch 23 October 2003 Intent: Add an additional profile Web Browser Artifact Profile Web Browser POST Profile LECP Profile Use Case Mobile phone user accesses web
Work Plan Item W-5a
– Minimize redirects
– Limited or no cookie support – URL length limitations – Scripting limitations (e.g. ECMAScript not supported)
– AuthnRequestEnvelope, AuthnResponseEnvelope – IDPList
– AuthnRequest, AuthnResponse
IDP LEC SP HTTP GET 1
AuthnRequest AuthnRequest SOAP AuthnResponse SOAP AuthnResponse
200, 0K …
–
Added optional Extension element
–
Added support for Affiliations, optional AffiliationID element
–
Added NameIDPolicy, ProxyAuthn, IntroductionArtifact, consent attribute
–
Removed Federate element, ID attribute
–
Changed name of AuthnContext to RequestAuthnContext, moved related elements to subelements
–
Added optional Extension element
–
Added optional consent attribute
–
Removed id attribute
–
Optional Extension element
–
Loc now required, previously optional
–
https://www.projectliberty.org/specs/draft-lib-arch-protocols-schema-v1.2-17.pdf
–
https://www.projectliberty.org/specs/archive/v1_1/liberty-architecture-bindings-profiles-v1.1.pdf
– Include LECP specific schema definitions
– AuthnRequest, AuthnResponse