Repeated Login with Shib (idp) and ADFS (sp)
Cantor, Scott
cantor.2 at osu.edu
Fri Feb 13 17:58:29 EST 2015
> Sorry to bother you again with this issue, but the people of the ADFS are
> blaming us that the double login it's our fault and not theirs (something that
> we think it's not true).
Can I borrow that phrase? People of the ADFS sounds like one of those prehistoric tribes, "people of the Mammoth".
> One question: Since the ADFS it's always answering with the attribute
> ForceAuth = true in the SAML AuthRequest when we access their WS-
> Federation URL resource, can we do something to prevent the ForceAuth to
> appear or there's nothing that we can do (us meaning Shib's Idp) to avoid the
> re-force-auth?
You can't do anything about the flag. The simplest solution is probably to point them at an intermediate script or something that that regenerates a new request without the flag, assuming you're not requiring signed requests, which I'm sure you're not.
-- Scott
More information about the users
mailing list