IdP config parameter for the maximum time of a full authentication
Wessel, Keith
kwessel at illinois.edu
Mon Mar 18 10:36:11 EDT 2019
Hi, all,
We've been seeing more stale sessions in our IdP logs and from reports from our users lately. A big part of this is the addition of the MFA step if the authentication process. If someone has to get their phone to finish logging in, they're often presented with a stale session after completing MFA if they took too long. Add the consent screen to the login process, and logins take a lot longer than they used to when they were only one UI screen long. I know one of the issues causing this is our SLB stickiness which is currently 5 minutes, and I plan to increase that. But it seems like the logins are encountering stale sessions in closer to three minutes.
Can any of the IdP config params such as idp.policy.messageLifetime which we have set to the default of 3 minutes, also limit the amount of aitme that a user has to get through the login process?
Thanks,
Keith
More information about the users
mailing list