maxTimeSinceAuthn FatalProfileException

Cantor, Scott cantor.2 at osu.edu
Fri Feb 12 15:04:14 UTC 2021


On 2/11/21, 8:37 PM, "dev on behalf of Dan McLaughlin via dev" <dev-bounces at shibboleth.net on behalf of dev at shibboleth.net> wrote:

>    When maxTimeSinceAuthn expires, is there a way to configure the SP to
>    redirect the user to the IDP with ForceAuthn=true instead of the
>    throwing the FatalProfileException - The gap between now and the time
>    you logged into your identity provider exceeds the limit.

All errors are the same, and the only thing you can do is a template or set redirectErrors and handle them yourself. So the answer is yes, the latter, and implementing the error handling to do what you want.

-- Scott




More information about the dev mailing list