...
Condition Evaluated | Reason | |||
R1 | md:IDPSSODescriptor element must have a signing certificate (ds:KeyDescriptor/ds:KeyInfo/ds:X509Data/ds:X509Certificate) | R2 | if md:Extentions element with md:UIInfo exists:
| [MDUI] sec. 2.1, [SAML] sec.1.3.1, [SAML] sec.1.3.2 |
R3R2 | if md:Extentions element with md:DiscoHints exist:
| [MDUI] sec.2.2, [SAML] sec.1.3.1, [SAML] 1.3.2, RFC5870 (for geo) | ||
R4R3 | mdui:Logo contains width and height attributes | |||
R5R4 | md:ServiceName element within md:AttributeConsumingService is not empty | SAMLMeta 2.4.4.1, SAML 1.3.1 | ||
R6R5 | md:AssertionConsumerService element Binding attribute does not contain urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect | |||
R7R6 | md:DiscoveryResponse element Binding attributes does not contain | [IdPDisco] sec.2.5 | ||
R8R7 | indexes in md:DiscoveryResponse, md:AssertionConsumerService, md:AttributeConsuminService are unique | [SAMLMeta] sec.2.2.3 |
...