Hi Emil,
> This is incorrect interpretation. SAML assumes that a user has previously
> authenticated against the Authentication Authority. The Authentication
> Request is a request for information about this previous event.
In the sample scenario, I am having www.abc.com authenticate the user
and not transferring any credentials to www.abc.com from www.xyz.com.
So there is no recognition of the user at www.xyz.com other than being
authenticated at the SAML Authority www.abc.com and then being vouched
for by sending Assertions for this "previous event".
Please provide comments or corrections.
-- Prasad.
____________________________________
Who ate my software ?