Corin.Langosch at Corin.Langosch at
Wed Oct 20 10:00:15 UTC 2021

Hi guys,

we are using shibboleth SP 3.1.0 and trying to get forced re-authentication to work.

In our configuration we have forceAuthn set to "true" but it seems shibboleth is always sending it as "1" in the XML auth request. According to this old post from 2019 of the keycloak mailing list ( also "1" is compliant with the spec and should be accepted.

However, the IDP we are integrating insists that only "true" or "false" are compliant and doesn't accept the answer given in the post mentioned above. "Whilst XML schemas may consider 1 as a valid boolean value, the SAML spec specifically states that the values should be true or false.<>"

Is our IDP right and thus this would need to be fixed in shibboleth? Or do they have to adjust their code? Thank you very much in advance.

Kind regards
