Modify forceAuthn Authentication Engine Behavior

Chad La Joie lajoie at itumi.biz
Thu Dec 15 21:40:41 GMT 2011


If applications care about sessions, then forceAuthn is what they need.

If, instead, the issue is that people are logging in and then walking
away and leaving their sessions, then it's not a software issue.
Unless your apps are authenticating users with every single request
made by the browser, then they have this issue.

On Thu, Dec 15, 2011 at 16:29, John Mitchell <jpmitchell at alaska.edu> wrote:
> On 12/15/2011 12:15 PM, Chad La Joie wrote:
>> Right, it will check to make sure it's the person who owns the session.
>>
>> So, how do you deal with this for any other application?  People
>> walking away and leaving sessions lying around isn't an IdP issue.
>>
>   Currently this is the first application that we have integrated that
> had these requirements and sadly we started down the Shib integration
> route without knowing it was a kiosk app. We have had other applications
> with this requirement and they have opted to not use Shibboleth in favor
> of other solutions (which was bad for the project).
>   Generally to speak to your question we depend on security measures at
> the desktop and good user behavior to protect the long lived sessions
> (comparatively speaking) which users have to do anyway since we use
> Google. I am wrestling with the issue of sessions and whether or not its
> an IdP issue or not for my organization. Since Shib is replacing another
> home grown web authn solution that did not have a notion of SSO, I am of
> the belief currently that we have to support short sessions  and that it
> is an IdP issue due to that migration or risk slow adoption or outright
> rejection. When I have more time I will probably explore the option of a
> short session IdP run in parallel with my existing IdP.

--
Chad La Joie
www.itumi.biz
trusted identities, delivered


More information about the dev mailing list