Modify forceAuthn Authentication Engine Behavior

Chad La Joie lajoie at itumi.biz
Thu Dec 15 21:15:30 GMT 2011


Right, it will check to make sure it's the person who owns the session.

So, how do you deal with this for any other application?  People
walking away and leaving sessions lying around isn't an IdP issue.

On Thu, Dec 15, 2011 at 16:09, John Mitchell <jpmitchell at alaska.edu> wrote:
> Chad,
>
> On 12/15/2011 12:05 PM, Chad La Joie wrote:
>> Thats what forceAuthn does.  So if the application always sends
>> forceAuthn, then there will be no SSO.
>>
>
>    It does but it expects the same principal to login each time
> forceAuthn is asserted when the IdP session is still valid right? That
> was what I read from looking at the validateForcedReauthentication
> method. In my applications case a different students will be logging
> into the application from the same web browser for very short
> application sessions. So setting the SPs session length very low and
> asserting forceAuthn does not appear to work as desired.
>
>> On Wed, Dec 14, 2011 at 20:18, John Mitchell <jpmitchell at alaska.edu> wrote:
>> For background: I am integrating an application
>>> that wishes to have absolutely no SSO due to running in a highly shared
>>> environment (kiosk that is used by students during registration). I am
>>> almost of the mind to setup another IdP to solve this problem, but I do
>>> not have the time and resources to do that right now.
>
>
> --
> John P. Mitchell <jpmitchell at alaska.edu>
> 907.450.8320
> http://www.alaska.edu/oit/iam
>
> "All mankind is divided into three classes: those that are immovable,
> those that are movable, and those that move." - Benjamin Franklin
>



-- 
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the dev mailing list