2007-12-16 06:42:00 by
Keith Brown in
Security Briefs
...helpful for issuing managed cards, which need to specify which claims an IdP supplies
What claims should be issued for a given user request, which consists of
Information about the target relying party (AppliesTo), which is not always known (an auditing STS will know this, for example
The AuthorizationContext for the user requesting the token...