Shibboleth IdP Authenticaiton requirement / design confirmation for authentication of Mobile User authentication

Cantor, Scott cantor.2 at osu.edu
Tue Dec 26 14:50:24 EST 2017


On 12/25/17, 4:39 PM, "dev on behalf of Ashok Vijayakumar" <dev-bounces at shibboleth.net on behalf of ashok.vijayk at gmail.com> wrote:

> 1)  Designing the user authentication via Shibboleth IdP login page loaded on to the native application web view and the 
> subsequent authentication should be via Shibboleth ECP End point

No. Usng a web view, which is a very reasonable to thing to do, is the exact opposite of using ECP, and would be relying on the standard Browser SSO profile.

> what is the alternative to achieve force authentication of user once in six months for mobile applicaiton?

By issuing your own token that you manage outside the IdP.

-- Scott




More information about the users mailing list