Disable SSO for Specific SP?
Timo Tunturi
timo.tunturi at aalto.fi
Fri Apr 28 11:42:58 EDT 2017
On 28/04/2017 16.59, Cantor, Scott wrote:
> On 4/28/17, 1:49 AM, "users on behalf of Tunturi Timo" <users-bounces at shibboleth.net on behalf of timo.tunturi at aalto.fi> wrote:
>
>> No, nor has anybody requested such a feature.
>>
>> It's a shame, because it (enforcing forceAuthn from the IdP side for
>> specific SPs) would really be a useful feature.
>
> Firstly, the MFA flow addresses this anyway, and secondly, you're regretting that nobody has aksed for a feature that you yourself have apparently not bothered to enter a RFE for?
This specific need only came about less than a week ago.
A client browser already has a valid global IdP session with a lower
grade authentication method. How can I disregard that session on the IdP
side for specific SPs and require them to to authenticate again with a
different method? Any pointer would be nice.
I already received advice to try and do this with an inbound
interceptor. Something I will look into unless I find that I'm a tool
and this can be acchieved with basic configuration.
>> The use case is to allow a only a specific authentication method (2FA)
>> for some SPs.
>
> That is not a use case for ForceAuthn.
I realize it shouldn't be. Thus far it just has been the only way I have
been somewhat able to disregard a global IdP session for particular SPs.
Somewhat on the same note, the Shibboleth SP side is not particularly
geared toward requiring a session with different methods of
authentication for different locations behind the same Shib SP.
Having exhausted my understanding with configuring the SP, the
authentication context class apache httpd env variable isn't available
during rewrite phase even with look-ahead.
-- Timo Tunturi
More information about the users
mailing list