Audit Authentication Events

Greg Haverkamp gahaverkamp at lbl.gov
Wed Jan 20 18:27:09 EST 2016


On Wed, Jan 20, 2016 at 7:05 AM, Marvin Addison <marvin.addison at gmail.com>
wrote:

> It seems like there ought to be a straightforward way to determine from
> audit logs whether a profile execution results in a new authentication or
> reuse of an existing one (i.e. SSO). Is there a way to do this out of the
> box?


As a proxy for my security folks, I added AuthenticationInstant to my audit
logs.  Comparing that to the event time was enough to give them most of
what they wanted, which was mostly to determine if an SSO session was used.
 (An actual indicator would be better still, though.)

Greg
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160120/8ef26e23/attachment.html>


More information about the users mailing list