Forced reauthentication

Jesse Santana Jesse.Santana at csulb.edu
Thu Aug 14 19:24:06 EDT 2014


Good to hear from you Dave – hope all is well.

Here is my entire Sessions block from the SP:

        <Sessions lifetime="28800" timeout="3600" relayState="ss:mem"
                  checkAddress="false" handlerSSL="false" cookieProps="http"
                  maxTimeSinceAuthn="5">

Should I be tuning all the numbers down to the same five seconds I have the maxTimeSinceAuthn value set to?

Jesse

Jesse Santana
Interim Director – Servers, Systems, and Websites
CSU Long Beach – Network Services
1250 Bellflower Blvd.
Long Beach, CA  90840
(562)985-8511


From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of David Langenberg
Sent: Thursday, August 14, 2014 4:18 PM
To: Shib Users
Subject: Re: Forced reauthentication

What's lifetime and timeout set to?

Dave

On Thursday, August 14, 2014, Jesse Santana <Jesse.Santana at csulb.edu<mailto:Jesse.Santana at csulb.edu>> wrote:
I’m really hoping to draw from the expertise of this community.

I currently have a Shibboleth IdP running (shibboleth-identityprovider version 2.4.0).  The instance is running as expected and releasing attributes to over a dozen SP’s that currently use it.  I have a new SP I’ve been asked to introduce to the environment with the requirement that this SP force re-authentication each time it is used.  I realize this goes against SSO in general but it is still a requirement I need to try and fill.

I’ve edit shibboleth2.xml (shibboleth 2.5.3) by adding to my “Sessions” block maxTimeSinceAuthn="5" and to my “SSO “ block forceAuthn="true".  After restarting my SP, I can login initially and see my session established on the SP:

INFO Shibboleth-TRANSACTION [10]: New session (ID: _7e76ca6eda3efe8ec9c547da21828981) with (applicationId: default) for principal

And I see the authentication on the IdP:

INFO [Shibboleth-Audit:1028] - 20140814T220328Z|urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect|_91a4358af7798cc5b9541c2dbcb13825

Along with my release of attributes.

When I close the tab in my browser that this application opened and reconnect to the application again in the same browser session, I can see where the SP logs a new session but the IdP is never contacted again for re-authentication.

What am I missing here?  Shouldn’t the SP contact the IdP again to re-authenticate and the IdP prompt me for my credentials again?

Thank you all in advance,

Jesse


Jesse Santana
Interim Director – Servers, Systems, and Websites
CSU Long Beach – Network Services
1250 Bellflower Blvd.
Long Beach, CA  90840
(562)985-8511




--
David Langenberg
Identity & Access Management
The University of Chicago

-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20140814/06622b87/attachment.html 


More information about the users mailing list