bypassing forceAuthn
David Langenberg
davel at uchicago.edu
Fri Jan 27 20:54:52 GMT 2012
Hi Devs,
I've noticed recently that an increasing number of SPs around my campus are
requiring forceAuthn in an attempt to take back control of the
user-auth/logout workflow. The typical argument they make is "think of the
kiosk users". Yeah Yeah, we've all had these same arguments with vendors &
SP admins at our own institutions. However, being an IdP admin and java
developer who hates typing his password more than once per day, I'd like to
write some kind of extension or plugin which would instruct the IdP to
ignore any forceAuthn requests for a particular list of users and just
forge the response to make the SP think it got what it asked for.
Before i proceed to just blindly hack this into the IdP, I was wondering if
someone would give me a pointer of the best way to add this new feature in
a pluggable & maintainable way so I wouldn't need to keep a set of diffs
around.
Thanks
Dave
--
David Langenberg
Identity Management
The University of Chicago
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/dev/attachments/20120127/3b3d3dfd/attachment.html
More information about the dev
mailing list