passive auth and login handlers

Cantor, Scott E. cantor.2 at osu.edu
Fri Aug 12 00:21:55 BST 2011


On 8/11/11 7:19 PM, "Paul Hethmon" <paul.hethmon at clareitysecurity.com>
wrote:

>SIDP-510
>
>My thought is that this should be a WARN, much as a Authn request with an
>invalid time would be. The error condition is expected and returning this
>type of response is the proper response when passive cannot be honored.

I would tend to say INFO, it's not anything unusual at all, just doing
what the site requested.

-- Scott



More information about the dev mailing list