> The last line seems to imply that the issuer would actually use the
> qualifiers etc.
If the format of the identifier makes that something worth doing, yes.
> But from what we discussed here it looks like the issuer will never use
> the attributes in the NameIDType, and it is basically just a string. Is
> this correct ?
In Web SSO, yes, it's a URI in fact, but the core spec is not specific to
Web SSO. What if I issue an assertion about somebody else and my identity is
expressed as a persistent ID?
-- Scott