CAS renew not honored in v3.4.1
Cantor, Scott
cantor.2 at osu.edu
Wed Dec 19 19:16:22 EST 2018
> I upgraded from IDP v3.3.1 to v3.4.1 recently. We have several CAS
> clients that are using the renew parameter to force a re-auth. We didn't
> notice until doing some testing today, but the IDP seems to be ignoring
> the renew parameter (it uses the SSO session and does not prompt for
> re-auth).
I see it processing the parameter so that doesn't seem possible unless the IdP's login methods are misdescribed. What's the login flow situation with it being used?
Ultimately it's up to the login flows themselves to honor it, but the IdP assumes if one is marked as supporting ForceAuthn that running it will do the right thing.
-- Scott
More information about the users
mailing list