Using Apache ShibRequestSetting authnContextClassRef and requesting new session

Douglas E. Engert deengert at anl.gov
Wed Apr 11 22:07:59 BST 2012



On 4/11/2012 3:57 PM, Cantor, Scott wrote:
>> But if I use user/password to authenticate first to access /protected.test
>> then try and access /protected.test.x509, I get an "Authentication Failed"
>> page.
>>
>> How can I get apache to request a new session using x509?
>
> The SP doesn't support step-up. If you want to create session boundaries, you have to implement them in the SP as separate applications. The admin portion of an app would have to explicitly identifiable by URL and then carved out as a separate applicationId.
>

Is that "step-down", in that using x509 currently gives access to both protected.test and protected.test.x509.
Would a separate applicationID still give the same behavior?


> -- Scott
>
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>
>

-- 

  Douglas E. Engert  <DEEngert at anl.gov>
  Argonne National Laboratory
  9700 South Cass Avenue
  Argonne, Illinois  60439
  (630) 252-5444


More information about the users mailing list