Element
AuthnStatement describes the authentication action in the identity provider. If the proxy authorized the entity, the statement MUST contain one representing this authentication event.
Example:
<AuthnStatement AuthnInstant="2010-10-01T20:07:34.371Z"> <AuthnContext> <AuthnContextClassRef> urn:oasis:names:tc:SAML:2.0:ac:classes:X509 urn:oasis:names:tc:SAML:2.0:ac:classes:Password urn:oasis:names:tc:SAML:2.0:ac:classes:Kerberos </AuthnContextClassRef> </AuthnContext> </AuthnStatement>
Element
SubjectConfirmation allows the authorization server to confirm it as a bearer confirmation. Such an element MUST have a Method attribute with the value "urn: oasis: names: tc: SAML: 2.0: cm: bearer". The SubjectConfirmation element MUST contain a SubjectConfirmationData element (with exceptions) that specifies the URL of the authorization server token endpoint. The authorization server MUST confirm that the value of the recipient attribute matches the URL of the endpoint of the token to which the claim was sent.
Example:
<saml:SubjectConfirmation> Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"> <saml:SubjectConfirmationData> InResponseTo="aaf23196-1773-2113-474a-fe114412ab72" Recipient="https://sp.example.com/SAML2/SSO/POST" NotOnOrAfter="2004-12-05T09:27:05"/> </saml:SubjectConfirmation>
source share