Is it possible for an IdP to service multiple SPs without SSO between SPs?

Cantor, Scott cantor.2 at osu.edu
Wed Sep 7 18:46:10 EDT 2016


On 9/7/16, 6:38 PM, "users on behalf of Eric Hattemer" <users-bounces at shibboleth.net on behalf of ehatteme at usc.edu> wrote:

>    Similar to the "defaultAuthenticationMethods" property in a
>    relying-party configuration, is there a way to inject the ForceAuthn
>    flag into the IDP side of an SP request that did not actually request
>    ForceAuthn?  Or would you perhaps have to duplicate the password flow
>    and modify it to always set ForceAuthn within the flow?

There is no such feature and login flows have no opportunity to get involved. If it's not set then the IdP will reuse a result before any flow got a chance to do anything about it.

-- Scott




More information about the users mailing list