Shibboleth IdP Authenticaiton requirement / design confirmation for authentication of Mobile User authentication
Cantor, Scott
cantor.2 at osu.edu
Tue Dec 26 14:50:24 EST 2017
On 12/25/17, 4:39 PM, "dev on behalf of Ashok Vijayakumar" <dev-bounces at shibboleth.net on behalf of ashok.vijayk at gmail.com> wrote:
> 1) Designing the user authentication via Shibboleth IdP login page loaded on to the native application web view and the
> subsequent authentication should be via Shibboleth ECP End point
No. Usng a web view, which is a very reasonable to thing to do, is the exact opposite of using ECP, and would be relying on the standard Browser SSO profile.
> what is the alternative to achieve force authentication of user once in six months for mobile applicaiton?
By issuing your own token that you manage outside the IdP.
-- Scott
More information about the dev
mailing list