ForceAuthn based on IDP entityId
Dan McLaughlin
dmclaughlin at tech-consortium.com
Fri Feb 12 01:30:25 UTC 2021
In our case we'd want all to have IDP's forcedAuthn=true except for
our internal IDP. Sounds like this isn't possible, am I
understanding you correctly?
--
Thanks,
Dan McLaughlin
Technology Consortium, LLC
dmclaughlin at tech-consortium.com
mobile: 512.633.8086
http://www.tech-consortium.com
NOTICE: This e-mail message and all attachments transmitted with it
are for the sole use of the intended recipient(s) and may contain
confidential and privileged information. Any unauthorized review, use,
disclosure or distribution is strictly prohibited. The contents of
this e-mail are confidential and may be subject to work product
privileges. If you are not the intended recipient, please contact the
sender by reply e-mail and destroy all copies of the original message.
On Thu, Feb 11, 2021 at 7:24 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 2/10/21, 10:52 PM, "dev on behalf of Dan McLaughlin via dev" <dev-bounces at shibboleth.net on behalf of dev at shibboleth.net> wrote:
>
> > Is there a way to configure the SP so ForceAuthn=true only for
> > specific IDP's? The use case is we want to allow SSO for our
> > internal IDP only, but for all other external IDP's we want
> > ForceAuthn=true.
>
> No, but the documentation says authnContextClassRef and NameIDFormat are customizeable, which means it's looking at the RelyingParty elements when it issues AuthnRequests. So I suspect it could and just isn't.
>
> -- Scott
>
>
More information about the dev
mailing list