Force authn context for IdP initiated calls

Cantor, Scott cantor.2 at osu.edu
Tue Oct 27 23:43:35 UTC 2020


On 10/27/20, 7:27 PM, "users on behalf of Scott Gilbert" <users-bounces at shibboleth.net on behalf of sgilbert at ucsb.edu> wrote:

>    Is there a way to force an IDP initiated authentication and return a SAML response for the authentication context of
> refeds? In other words is there a way to configure a service provider for a specific authentication context overriding what
> they request upon authentication? The IdP will always return this authn context for this SP.

Controlling it IdP side is documented under the profile configuration section with examples. IdP-initiated is immaterial to the use case, it applies either way since the vast majority of SPs can't request anything and if they do they usually botch the "check it afterwards" step.

https://wiki.shibboleth.net/confluence/display/IDP4/SAML2SSOConfiguration

It's under Authentication.

The tabbed add-in I'm using for the documentation changes recently will find their way into that section and make it much more readable than it is, I'm aware it's a mess.

-- Scott




More information about the users mailing list