Skip to content

add default aal authn context#38

Merged
achapm merged 1 commit intomainfrom
add-default-aal-authn-context
Apr 7, 2021
Merged

add default aal authn context#38
achapm merged 1 commit intomainfrom
add-default-aal-authn-context

Conversation

@achapm
Copy link

@achapm achapm commented Apr 6, 2021

WHY:
If a service provider passes the default aal value (urn:gov:gsa:ac:classes:sp:PasswordProtectedTransport:duo) in the authn contexts it will not be recognized or returned in requested_aal_authn_context.

Copy link

@aduth aduth left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

👍

Just to clarify, we'd not want to return the default value as a fallback from requested_aal_authn_context because the method is intended to return only what's been requested by an SP, and the defaulting behavior in the IDP isn't sufficient because it may try for an IAL context before returning the IAL default value?

@achapm achapm merged commit fd7c822 into main Apr 7, 2021
@achapm achapm deleted the add-default-aal-authn-context branch April 7, 2021 13:07
@achapm
Copy link
Author

achapm commented Apr 7, 2021

Thanks @aduth for the clarification

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants