...
- Tooling packages readily available for processing messages.
- WS-Trust, etc already support the forwarding and processing of delegated credentials.
- Shib's CS support would have to support the use of holder-of-key.
Develop a New SAML Profile
- Not Browser based.
- Flow originates at the client (no Authn Request from the SP).