Details
-
New Feature
-
Status: Closed
-
Major
-
Resolution: Fixed
-
2.6.1
-
None
-
Unknown
Description
The OneTimeUse element is specified in secton 2.5.1.5 of the SAML core specification:
http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf
CXF service endpoint doesn't process the OneTimeUse.
Maybe the STS should set this flag if the following attribut is set:
/wst:RequestSecurityToken/wst:Renewing/@Allow=False