requiring MFA for an unsolicited SSO SP
Klingenstein, Nate
nklingenstein at calstate.edu
Mon Sep 19 16:18:38 EDT 2016
There has never been a feature to control ForceAuthn. Nor has anybody ever requested it to my knowledge.
I was running through the fields that signing requests is useful for. If I found a flag for one, I'd expect to find a flag for the other.
It's just enforcing policy on the SP's behalf, after all.
The other that came to mind is endpoint checking, but that fails closed anyway.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160919/b9e33266/attachment.html>
More information about the users
mailing list