generated from martinthomson/internet-draft-template
-
Notifications
You must be signed in to change notification settings - Fork 7
Open
Description
SAML implementations should include security best practices due to variable nature of NameID
Refresh tokens are related because SAML assertions are more short lived than id_tokens, commonly, causing the client to execute all id-jag requests within its lifetime.
Additionally it should be clear SAML can only be support for requesting apps, as the resource apps must implement Oauth (maybe that is overly obvious, though)
Metadata
Metadata
Assignees
Labels
No labels