From various discussions held with various folks, e.g. on the IDWorkshop mailing list, it has become apparent that the major sticking point w.r.t. adoption in some quarters, e.g. in the "scripting" world (e.g. PHP/Perl/Python/Ruby), is mandated reliance on (aka "XMLdsig"). Interoperable XMLdsig libraries are hard to come by, perhaps due to the XMLdsig spec's complexity and reliance on "" (aka "c14n") which is inherently complex on its own. So Scott Cantor and I have hacked up this draft alternative SAMLv2 HTTP POST "NoXMLdsig" binding.

now the next step will be to craft a samlv2 profile that takes advantage of it.

