Audit Authentication Events
Greg Haverkamp
gahaverkamp at lbl.gov
Wed Jan 20 18:27:09 EST 2016
On Wed, Jan 20, 2016 at 7:05 AM, Marvin Addison <marvin.addison at gmail.com>
wrote:
> It seems like there ought to be a straightforward way to determine from
> audit logs whether a profile execution results in a new authentication or
> reuse of an existing one (i.e. SSO). Is there a way to do this out of the
> box?
As a proxy for my security folks, I added AuthenticationInstant to my audit
logs. Comparing that to the event time was enough to give them most of
what they wanted, which was mostly to determine if an SSO session was used.
(An actual indicator would be better still, though.)
Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160120/8ef26e23/attachment.html>
More information about the users
mailing list