ForceAuthn based on IDP entityId
Dan McLaughlin
dmclaughlin at tech-consortium.com
Fri Feb 19 03:02:35 UTC 2021
Is there a way to cause maxTimeSinceAuthn to trigger a redirect to the
IDP for authentication with ForceAuthn=true instead of throwing a
"FatalProfileException - The gap between now and the time you logged
into your identity provider exceeds the limit."
--
Thanks,
Dan
On Fri, Feb 12, 2021 at 9:11 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 2/11/21, 8:30 PM, "Dan McLaughlin" <dmclaughlin at tech-consortium.com> wrote:
>
> > In our case we'd want all to have IDP's forcedAuthn=true except for
> > our internal IDP. Sounds like this isn't possible, am I
> > understanding you correctly?
>
> It's not possble.
>
> -- Scott
>
>
More information about the dev
mailing list