Implications of forceAuthn/AuthnInstant
Cantor, Scott
cantor.2 at osu.edu
Thu Oct 10 12:38:11 EDT 2013
On 10/10/13 12:28 PM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:
>
>Is the implication of this statement that the following two scenarios are
>equivalent (from a security point of view)?
More or less.
>Scenario A
>1) SP sends ForceAuthn in AuthnRequests
>2) SP enforces maxTimeSinceAuthn on incoming assertions
>
>
>Scenario B
>1) SP sends ForceAuthn in AuthnRequests
>2) SP AuthnRequest are signed
>3) SP operator ensures that any relied upon IdPs honor and support
>ForceAuthn
I would say rather that have to properly conform to the standard. They
don't have to support it, they just can't ignore it.
>
>4) SP operator ensures that any relied upon IdPs require signed
>AuthnRequests from this SP
>
>
>I grant that in scenario A there's still an implicit requirement that for
>logins to work the SP operator must ensure all IdPs honor the ForceAuthn,
>there's just less security risk in scenario A's failure mode if that is
>not done.
>From a certain perspective I guess, but as you've said if you can't really
trust that people are going to set AuthnInstant properly, the risk seems
to be about the same. It's just not as difficult an issue as requiring
signed requests would be, which is why we have never gone that direction.
-- Scott
More information about the users
mailing list