CAS renew not honored in v3.4.1
Cantor, Scott
cantor.2 at osu.edu
Wed Dec 19 20:33:02 EST 2018
On 12/19/18, 8:26 PM, "users on behalf of Andrew Morgan" <users-bounces at shibboleth.net on behalf of morgan at orst.edu> wrote:
> I have idp.authn.favorSSO = false because we needed the MFA flow to run on
> every auth request. I'm not sure if that is relevant here.
Not necessary anymore, but it shouldn't matter.
> Any other info I can share that will help? Is there is any logging to
> turn on?
On debug, I think it should log something somewhere about the state of the authentication context and that should dump out the forceAuthn flag stored in it at the point it's starting the login step.
Apart from that, just seeing at a detailed level what happens during authentication I guess. Where the appearance of SSO is really coming from.
I have to assume something is interfering and preventing the parameter from being visible to the CAS code to get it set, but the code that's checking for it is the exact same bit that pulls out the service parameter, so it's not like it's getting skipped.
-- Scott
More information about the users
mailing list