requiring MFA for an unsolicited SSO SP

Klingenstein, Nate nklingenstein at calstate.edu
Mon Sep 19 16:18:38 EDT 2016


There has never been a feature to control ForceAuthn. Nor has anybody ever requested it to my knowledge.

I was running through the fields that signing requests is useful for.  If I found a flag for one, I'd expect to find a flag for the other.

It's just enforcing policy on the SP's behalf, after all.

The other that came to mind is endpoint checking, but that fails closed anyway.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160919/b9e33266/attachment.html>


More information about the users mailing list