requiring MFA for an unsolicited SSO SP
Klingenstein, Nate
nklingenstein at calstate.edu
Mon Sep 19 15:58:39 EDT 2016
I think we need to go ahead and implement a profile setting that disallows (meaning errors out) on any SAML request that tries to specify the authentication context. If you file that, I'll get it into 3.3.
Orthogonal to the use case at hand, but does the same apply to forceAuthn?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160919/73067b67/attachment-0001.html>
More information about the users
mailing list