[JIRA] Created: (SIDP-519) Switching between multiple login handlers cause first context to be sticky in Shib-Authentication-Method
Stefan (JIRA)
noreply at shibboleth.net
Mon Sep 5 19:40:25 BST 2011
Switching between multiple login handlers cause first context to be sticky in Shib-Authentication-Method
---------------------------------------------------------------------------------------------------------
Key: SIDP-519
URL: https://issues.shibboleth.net/jira/browse/SIDP-519
Project: Shibboleth IdP 2 - Java
Issue Type: Bug
Security Level: Standard (Standard bug, may impact functionality but does not represent a security vulnerability )
Components: Authentication
Affects Versions: 2.3.3, 2.3.2
Environment: Linux 2.6.35-30-server, 64-bit. OpenJDK 1.6.0_20, tomcat 6.0.32
IdP extensions: Multi Factor Login Handler, MongoDB connector
Reporter: Stefan
Assignee: Chad La Joie
I have two login handlers, one is UserPassword and the other is MultiFactor (2FA). The problem I have is that the first authn context loaded is the one that seem to get sticky when Shib-Authentication-Method attribute is released to the SP.
Example:
The SP request MultiFactor handler but the user decide to manually override it by editing the URL from /MultiFactor to /UserPassword and then completes the login using one factor. Now I expect to be Shib-Authentication-Method = urn:oasis:names:tc:SAML:2.0:ac:classes:PasswordProtectedTransport, but instead it's Shib-Authentication-Method = urn:oasis:names:tc:SAML:2.0:ac:classes:Token. And vice versa if the SP request UserPassword and the user change it to MultiFactor.
I have tried requesting a login handler from the SP or letting the IdP choose a default login handler both with same result.
--
This message is automatically generated by JIRA.
For more information on JIRA, see: http://www.atlassian.com/software/jira
More information about the commits
mailing list