Forced Authn and IdPUnsolicitedSSO
Nate Klingenstein
ndk at internet2.edu
Tue Aug 5 13:43:11 EDT 2014
Eric,
I may be stating the obvious, but the only way you can really enforce the forcedauthn is if the SP actually checks the resultant assertion for how old it is.
I think the SP is responsible for enforcing any check regardless, and most of the data available to it comes from the IdP. In both these cases, you're relying on the IdP to accurately represent what has occurred, no matter what "what" is, and you don't really have a good way of validating that beyond trusting that specific IdP.
There are ways that I could imagine the SP could "whisper to itself" which would be indicative, but not especially conclusive.
Hope I'm missing the obvious...
Nate.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140805/b2a20f04/attachment.html
More information about the users
mailing list