Do IDP logs indicate forced or passive authn requests?

Rod Widdowson rdw at steadingsoftware.com
Sat Mar 29 08:12:54 EDT 2014


If I'm reading the source correctly (and it is but a skim) there may not be
anything at any sane level, but if you turn just this class

edu.internet2.middleware.shibboleth.idp.authn.AuthenticationEngine

to be debug, you should see messages saying:

"Passive authentication is required, filtering poassible login handlers
accordingly."

But that looks like a pretty noisy class so this will probably be too much.

/Rod

> -----Original Message-----
> From: users-bounces at shibboleth.net [mailto:users-
> bounces at shibboleth.net] On Behalf Of Wessel, Keith
> Sent: 29 March 2014 04:15
> To: users at shibboleth.net
> Subject: Do IDP logs indicate forced or passive authn requests?
> 
> Hi, all,
> 
> I think the answer is no. I'm trying to figure out from IDP logs (running
at a
> sane logging level for production) which of our SPs are using forced or
> passive authentication. Other than exceptions written to the log when a
user
> tries to change identities from a forced auth request on an active
session, I'm
> not seeing anything in my IDP logs related to forced or passive authn. Am
I
> missing something? Is there something that gets logged to indicate a
request
> of these types has been received? Or is it logged like any other request?
> 
> Thanks,
> Keith
> 
> --
> To unsubscribe from this list send an email to users-
> unsubscribe at shibboleth.net



More information about the users mailing list