MFA flow and individual timeouts for individual results within the MFA flow
Cantor, Scott
cantor.2 at osu.edu
Tue Jun 27 12:50:15 EDT 2017
On 6/27/17, 12:45 PM, "users on behalf of Scott Koranda" <users-bounces at shibboleth.net on behalf of skoranda at gmail.com> wrote:
> Is it possible that being able to manage individual timeouts could be added for a future release, say 4.0?
I don't think it's practical in the specific case of the IdP managing SSO, but the change to bypass that is already made, so if you're managing that yourself, I believe you should be able to poke in updates to the last-access field in your MFA ruleset, so that way you control what it "means" to be reusing things.
Also, if you do get the MFA flow to run, and you signal a login flow to run, and it auto-reuses the result for you, it will update the field for you too.
So, I think this is done insofar as it's possible to do it.
-- Scott
More information about the users
mailing list