> Hi when you say reasobly clean in SAML 2.0,
> do you mean Liberty based on SAML 2.0 ?
No, I meant that the semantics can be expressed in a relatively reasonable
way in SAML 2.0 but not in SAML 1.1.
> I didn't see a solution using a pure SAML 2.0 approach.
> I'm kind of interested in finding some SAML specific approach
> (for semplicity and to build a prove of concept)
> How would you approach this problem ? Any idea ?
My straw man on how one *might* consider doing it is an individual
submission to the Shibboleth project.
https://authdev.it.ohio-state.edu/twiki/bin/view/Shibboleth/ShibPortals
-- Scott