force re-authentication.
Manuel Haim
haim at hrz.uni-marburg.de
Thu Aug 29 10:53:11 EDT 2013
Hi Brent,
did you restart the SP (shibd) and Apache after configuration change?
The maxTimeSinceAuthn option should tell the SP that, if the last IdP
authentication was done more than e.g. 30 seconds ago, the user shall
re-authenticate at the IdP.
If you test this, please keep in mind that at least 30 seconds have to
pass from your initial login till trying the "forced" authentication.
(If not using an <ApplicationOverride> containing another <Sessions>
element, all shib-protected resources run under the same SP session.)
-Manuel
Am 29.08.2013 16:12, schrieb Nickles, Brent:
> Manuel, thanks for the reply.
> The owner of the SP put this in the shibboleth2.xml file; however
> the results are the same. Any other ideas to force re-authN?
>
> Thanks
> Brent
>
> -----Original Message-----
> From: users-bounces at shibboleth.net
[mailto:users-bounces at shibboleth.net] On Behalf Of Manuel Haim
> Sent: Monday, August 26, 2013 10:56 AM
> To: users at shibboleth.net
> Subject: Re: force re-authentication.
>
> Hi Brent,
>
> Am 26.08.2013 16:06, schrieb Nickles, Brent:
>> but if you first go into the auth resource, then the forcereauth
>> resource it doesn't prompt for credentials
>
> you also need to set maxTimeSinceAuthn in your <Sessions> node in
order to make this work as expected (but not too low, e.g. to 30 seconds).
>
> -Manuel
> --
> To unsubscribe from this list send an email to
users-unsubscribe at shibboleth.net
>
More information about the users
mailing list