Session Lifetime of constituent flows in MFA
John Watt
John.Watt at glasgow.ac.uk
Fri Mar 4 15:59:23 UTC 2022
With reference to the SessionConfiguration settings advance example regarding lifetime and timeouts:
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631620/SessionConfiguration#Advanced-Session-Lifetime-Example
Is this scenario (where the authn/X509 has its own longer lifetime override) honoured when these flows are invoked from an MFA flow?
There was a call two years ago on a different issue (Forcing the timeout of 2nd factor in a MFA login) where a reply was given:
"I believe the timeout settings in the beans in general-authn are applied to the particular flow that was called. I *believe* they become irrelevant if the flows are called via another flow (in this case, password is called via the mfa flow, so the only timeout setting that would be evaluated is the one for the mfa flow itself)."
If this is true, does this apply to the lifetime settings as well?
Thanks,
John
----------------------------------------------------------------------
Dr. John Watt
IT Services, Room 1006, Library
University of Glasgow, Glasgow G12 8QQ
T 0141 330 8647 | M 07545 500579
The University of Glasgow, charity number SC004401
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220304/8eb34b63/attachment.htm>
More information about the users
mailing list