forceAuthn behavior

Manolo Garcia Alvarez mgarciaal at uoc.edu
Wed Dec 19 08:48:06 EST 2018


Thanks for your comments.

We have discovered the problem, it was a misconfiguration in the
authentication filter, it's ignoring the forceAuth parameter.

Bes regards.

------------------------------
Manolo García
Arquitectura i Sistemes
Universitat Oberta de Catalunya

93 326 (3451) | 689 88 30 93 | mgarciaal at uoc.edu
Parc Mediterrani de la Tecnologia (edifici B3)
Av. Carl Friedrich Gauss, 5.
08860 Castelldefels
[image: Universitat Oberta de Catalunya]
Aquest missatge s'adreça exclusivament a qui va destinat i pot contenir
informació privilegiada o confidencial i dades de caràcter personal, la
difusió de les quals és regulada per la Llei orgànica de protecció de dades
i la Llei de serveis de la societat de la informació. Si no sou la persona
destinatària indicada (o la responsable de lliurar-lo a qui va destinat),
no heu de copiar aquest missatge ni lliurar-lo a tercers per cap concepte.
Si heu rebut aquest missatge per error o l'heu aconseguit per altres
mitjans, us demanem que ens ho comuniqueu immediatament per aquesta mateixa
via i l'elimineu irreversiblement.

Abans d'imprimir aquest missatge electrònic penseu en el medi ambient.


El mié., 19 dic. 2018 a las 11:45, Peter Schober (<
peter.schober at univie.ac.at>) escribió:

> * Manolo Garcia Alvarez <mgarciaal at uoc.edu> [2018-12-19 08:54]:
> > Our problem is caused by this lack of synchrony: A CAS session may expire
> > much earlier than the Shibboleth session. We have tried to avoid the
> > problem using the forceAuthn in the SAML Request, but Shibboleth is not
> > behaving as expected and it's returning a CAS session that's expired.
>
> You're didn't mention the exact integration method between your Shib
> IDP and your CAS server. (I believe there are several ways to do this.)
> Probably that's just been done in a way that does not support
> forceAuthn (nor isPassive, I'm guessing)?
>
> Also note that the Shib IDP supports the CAS protocol itself and so
> you might get several benefits out of using that instead of having to
> run two separate SSO systems.
>
> -peter
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20181219/03e90db3/attachment.html>


More information about the users mailing list