Repeated Login with Shib (idp) and ADFS (sp)
Thomas Jones
thomas.jones.g at gmail.com
Fri Feb 13 18:25:05 EST 2015
>
> Can I borrow that phrase? People of the ADFS sounds like one of those
> prehistoric tribes, "people of the Mammoth".
>
LOL! Totally Agree!! (I won't be able to see them as the ADFS people
anymore)
> > One question: Since the ADFS it's always answering with the attribute
> > ForceAuth = true in the SAML AuthRequest when we access their WS-
> > Federation URL resource, can we do something to prevent the ForceAuth to
> > appear or there's nothing that we can do (us meaning Shib's Idp) to
> avoid the
> > re-force-auth?
>
> You can't do anything about the flag. The simplest solution is probably to
> point them at an intermediate script or something that that regenerates a
> new request without the flag, assuming you're not requiring signed
> requests, which I'm sure you're not.
>
>
Thanks a lot, it makes sense.
I really appreciate your help!
Best,
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20150213/43bda058/attachment-0001.html
More information about the users
mailing list