extend shibb SP authentication request validity
Sathyaprasad, Sandeep (NIH/CIT) [C]
sathyaprasads at mail.nih.gov
Wed Sep 16 15:27:12 UTC 2020
Hello,
We have a case where our SP sends out an authentication request to an external IDP and users have to go through a registration process at the IDP and this process takes about 15 mins. After the user has completed the registration process they are redirected back with a SAML assertion to our Shibb SP and we can see that the SAML assertion is consumed but the users aren't being redirected to the relay state parameter in the URL instead they are being taken to the root of the ACS URL. We have observed this behavior whenever it takes more than 10 mins for the SAML assertion to be sent by the IDP. So, it looks like by default Shibb SP expects a SAML assertion from an IDP with in 10 mins of sending out an authentication request.
Is there a way to increase the shibb SP authentication request validity period so that our SP is able to redirect the users to the relay state parameter after consuming the SAML assertion?
Thanks,
Sandeep
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200916/568aab6a/attachment.htm>
More information about the users
mailing list