Implications of forceAuthn/AuthnInstant

Cantor, Scott cantor.2 at osu.edu
Thu Oct 10 18:48:23 EDT 2013


On 10/10/13 6:41 PM, "Eric Goodman" <Eric.Goodman at ucop.edu> wrote:

>Thanks again.
>
>>4) SP operator ensures that any relied upon IdPs require signed
>>AuthnRequests from this SP
>
>I made an assumption here that requiring signed AuthnRequests can be done
>on an SP-by-SP basis. Is SP-by-SP control possible?
>
>It appears that requiring AuthnRequest signing would be done in
>relying-party.xml in the SecurityPolicy section for the relevant protocol
>(e.g., shibboleth.SAML2SSOSecurityPolicy) by adding the appropriate rule
>(security:MandatoryMessageAuthentication?) But those rules look fairly
>global to the RelyingPartyGroup element, and not clearly scopeable to
>individual RPs or ProfileConfigurations.

I believe the schema allows specific RelyingParties to be associated with
a ruleset but Brent would know better than I would.

It certainly isn't something anyone has tried to do, to my knowledge.

-- Scott




More information about the users mailing list