Disable SSO for Specific SP?

Timo Tunturi timo.tunturi at aalto.fi
Fri Apr 28 11:42:58 EDT 2017


On 28/04/2017 16.59, Cantor, Scott wrote:
> On 4/28/17, 1:49 AM, "users on behalf of Tunturi Timo" <users-bounces at shibboleth.net on behalf of timo.tunturi at aalto.fi> wrote:
> 
>> No, nor has anybody requested such a feature.
>>
>> It's a shame, because it (enforcing forceAuthn from the IdP side for
>> specific SPs) would really be a useful feature.
> 
> Firstly, the MFA flow addresses this anyway, and secondly, you're regretting that nobody has aksed for a feature that you yourself have apparently not bothered to enter a RFE for?

This specific need only came about less than a week ago.

A client browser already has a valid global IdP session with a lower 
grade authentication method. How can I disregard that session on the IdP 
side for specific SPs and require them to to authenticate again with a 
different method? Any pointer would be nice.

I already received advice to try and do this with an inbound 
interceptor. Something I will look into unless I find that I'm a tool 
and this can be acchieved with basic configuration.

>> The use case is to allow a only a specific authentication method (2FA)
>> for some SPs.
> 
> That is not a use case for ForceAuthn.

I realize it shouldn't be. Thus far it just has been the only way I have 
been somewhat able to disregard a global IdP session for particular SPs.

Somewhat on the same note, the Shibboleth SP side is not particularly 
geared toward requiring a session with different methods of 
authentication for different locations behind the same Shib SP.

Having exhausted my understanding with configuring the SP, the 
authentication context class apache httpd env variable isn't available 
during rewrite phase even with look-ahead.

-- Timo Tunturi


More information about the users mailing list