Occasional SAML exception during SP/IdP handshake
Saimon Moore
saimonmoore at gmail.com
Wed Jul 31 12:50:30 EDT 2013
Thanks again Scott. I'll pass on this information to the IdP.
On 31 Jul 2013 18:30, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
> On 7/31/13 11:38 AM, "Saimon Moore" <saimonmoore at gmail.com> wrote:
> >
> >I put on my thinking cap and realised that I had forceAuthn set to true
> >in shib2.xml config and this is why the existing session wasn't be reused.
>
> If their login handler chosen does not support ForceAuthn, then the IdP is
> behaving correctly by returning the error.
>
> >So in reality I was asking the idp to reauthenticate while an existing
> >session already existed. It may be that the IdP has an issue with this
> >when the session cookies exist for the user retrying the authentication.
>
> No, the issue is they use a login handler that doesn't happen to support
> the option. Many will not.
>
> -- Scott
>
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20130731/61438874/attachment.html
More information about the users
mailing list