For auditing purposes

SVS tech log - check!

  1. Incoming Authentication request from RP
  2. Entity id of IdP selected by the user: response returned from the discovery server
  3. Authentication request/response to/from IdP
  4. Authentication response delivered back to RP

SVS anonymised log

  1. All transactions of a specific IdP
  2. All transactions of a specific SP
  3. Transactions per SP and IdP

Log error situations as well -> Yes! Niels provides more requirements, but not now.

MDQ log

  1. Incoming request + outgoing response

Identified challenges