Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

For IdPs that are not Silver-capable according to metadata, the SP does not include an IAQ in the SAML AuthnRequest element. For IdPs that are Silver-capable according to metadata, the SP includes http://id.incommon.org/assurance/silver and http://id.incommon.org/assurance/bronze and http://id.incommon.org/assurance/basic in the in the SAML AuthnRequest element. It accepts at Silver LOA assertions that contain http://id.incommon.org/assurance/silver in the AuthnContext from IdPs with http://id.incommon.org/assurance/silver in their InCommon metadata. The SP applies compensating controls for all other assertions (considered to be lower LOA).

Note: http://id.incommon.org/assurance/basicImage Added is just a straw-man proposal.

Examples:

  • CILogon

UC3: SP Prefers Bronze

...