Oliver Wulff created CXF-4442: --------------------------------- Summary: Process OneTimeUse element of SAML assertion Key: CXF-4442 URL: https://issues.apache.org/jira/browse/CXF-4442 Project: CXF Issue Type: New Feature Components: WS-* Components Affects Versions: 2.6.1 Reporter: Oliver Wulff
The OneTimeUse element is specified in secton 2.5.1.5 of the SAML core specification: http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf CXF service endpoint doesn't process the OneTimeUse. Maybe the STS should set this flag if the following attribut is set: /wst:RequestSecurityToken/wst:Renewing/@Allow=False -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators: https://issues.apache.org/jira/secure/ContactAdministrators!default.jspa For more information on JIRA, see: http://www.atlassian.com/software/jira