Premature Authn Result Expiration w/MFA

Marvin Addison marvin.addison at gmail.com
Mon Sep 19 09:53:32 EDT 2016


We have deployed the new MFA framework in a recent 3.3.0 snapshot to
production last week and since we've noticed what appears to be premature
authentication result expiration. I have reviewed all the configuration
that I can think to check, and everything appears configured as needed to
provide the policy we want; namely that authentication results do _not_
time out prior to the IdP session that lasts 24h. Instead it looks like
they're timing out on the order of the default 60m.

I don't see any new MFA-specific knobs related to timeouts, nor do I see
how this could arise naturally from the composition of authentication flows
via the MFA orchestration. Any suggestions or thoughts on what's happening?

Thanks,
Marvin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160919/de56d31f/attachment.html>


More information about the users mailing list