As far as I know, to request an OnBehalfOf Token should not simply result in adding a related SAML Attribute (as it would be ok for ActAs). OnBehalfOf should deliver a Token where "only" the OnBehalfOf Principal is contained. Therefor the SAML Subject should match the requested OnBehalfOf Principal and not the Principal which was authenticated based on the security token sent in the WS-Security header...