Occasional SAML exception during SP/IdP handshake
Cantor, Scott
cantor.2 at osu.edu
Wed Jul 31 12:30:27 EDT 2013
On 7/31/13 11:38 AM, "Saimon Moore" <saimonmoore at gmail.com> wrote:
>
>I put on my thinking cap and realised that I had forceAuthn set to true
>in shib2.xml config and this is why the existing session wasn't be reused.
If their login handler chosen does not support ForceAuthn, then the IdP is
behaving correctly by returning the error.
>So in reality I was asking the idp to reauthenticate while an existing
>session already existed. It may be that the IdP has an issue with this
>when the session cookies exist for the user retrying the authentication.
No, the issue is they use a login handler that doesn't happen to support
the option. Many will not.
-- Scott
More information about the users
mailing list