Modify forceAuthn Authentication Engine Behavior

Cantor, Scott cantor.2 at osu.edu
Fri Dec 16 00:27:26 GMT 2011


On 12/16/11 12:50 AM, "Chad La Joie" <lajoie at itumi.biz> wrote:
>
>But again, the only actual solution is to either require
>authentication for every single request or educate the user so they
>don't do dumb things.

That would be true if there was anything the user could do to actually
terminate the IdP session, but that isn't generally feasible with modern
browsers and the typical kiosk.

I don't think forceAuthn is implemented incorrectly, and I would say that
the AuthnContext solution is probably the right one. But that only works
if you can react to the error at the IdP that blocks principal switching
with some user action, and I can't think what that would be at the moment.

-- Scott



More information about the dev mailing list