Repeated Login with Shib (idp) and ADFS (sp)

Thomas Jones thomas.jones.g at gmail.com
Fri Feb 13 17:48:01 EST 2015


Hi Scott,

Sorry to bother you again with this issue, but the people of the ADFS are
blaming us that the double login it's our fault and not theirs (something
that we think it's not true).

*One question: *Since the ADFS it's always answering with the attribute
ForceAuth = true in the SAML AuthRequest when we access their WS-Federation
URL resource, can we do something to prevent the ForceAuth to appear or
there's nothing that we can do (us meaning Shib's Idp) to avoid the
re-force-auth?

Thanks again for all your help.

Best,

On Fri, Jan 23, 2015 at 9:24 AM, Cantor, Scott <cantor.2 at osu.edu> wrote:

> On 1/23/15, 1:02 PM, "Thomas Jones" <thomas.jones.g at gmail.com> wrote:
>
>
> >
> >1. Do you know if there's something that can be done on Shib's Idp side
> >when it receives this SAML AuthnRequest (that has the ForceAuthn = true)
> >and get from a session or a cookie info that can used to create a SAML
> >Response that doesn't require to force the user to a whole authentication
> >process (somehow a silent authentication)?
>
> That would be a violation of the spec, but how you authenticate people is
> up to you in the end.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150213/7cb2b242/attachment.html 


More information about the users mailing list