diff options
| author | Benjamin Dauvergne <bdauvergne@entrouvert.com> | 2009-03-03 20:52:49 +0000 |
|---|---|---|
| committer | Benjamin Dauvergne <bdauvergne@entrouvert.com> | 2009-03-03 20:52:49 +0000 |
| commit | f64f9973a551f3e29f367f633078ab0c467045f6 (patch) | |
| tree | ee459d6081a1be161ce38d6538b963b344474bed /java/tests/LoginTest.java | |
| parent | b744d0be87b7788ef67e1627f50d264dbc690881 (diff) | |
| download | lasso-f64f9973a551f3e29f367f633078ab0c467045f6.tar.gz lasso-f64f9973a551f3e29f367f633078ab0c467045f6.tar.xz lasso-f64f9973a551f3e29f367f633078ab0c467045f6.zip | |
SAML 2.0: remove NotBefore attribute when not answering an AuthnRequest
* lasso/saml-2.0/login.c:
In specification saml-profile-2.0-os.pdf, in paragraph 4.1.4.3, it is
said that the SubjectConfirmationData node MUST NOT contain a
NotBefore attribute if it contains an InReponseTo attribute,
understanding that the response cannot (it the ID of the request is
sufficiently random) arrive before the request and be valid with
respect to the InResponseTo attribute.
Diffstat (limited to 'java/tests/LoginTest.java')
0 files changed, 0 insertions, 0 deletions
