AuthnContextClassRef in authentication request from sp seem to be ignored by idp
iljkr at tiscali.it
iljkr at tiscali.it
Mon Jan 23 13:16:37 UTC 2023
Goog morning,
we are migrating from idp2 to idp4. With idp2 all
works fine, with idp4 we are found some problems.
In particular, we
would like to ask for support on this issue: the values in
AuthnContextClassRef sent in the authentication request from the Sps
seem to be ignored.
The sso doesn't seem to take this into account, just
an example what I mean:
1) I login with an sp that sends in the saml
request "samlp:RequestedAuthnContext Comparison="exact" and
"urn:federation:ac:classes:PasswordProtectedTransport" in
AuthnContextClassRef .
2) I try to access to another SP configured to
send "samlp:RequestedAuthnContext Comparison="exact" and
"urn:federation:ac:classes:X509Q" in AuthnContextClassRef . I would
expect to see the login screen again, but the idp responds immediately
with a successful authentication response.
I use flow External
Authentication.
In the old idp2, we don't have this behavior, are we
missing something that needs to be configured?
Thanks
VOUCHER CONNETTIVITÀ per P.IVA e PMI: internet a canone 0 per 48 mesi. ATTIVA ORA
https://casa.tiscali.it/promo/?u=https://promozioni.tiscali.it/voucher_business/?r=TS00000A00025&dm=link&p=tiscali&utm_source=tiscali&utm_medium=link&utm_campaign=voucherbusiness&wt_np=tiscali.link.footermail.voucherbusiness.btb..
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230123/488d07b6/attachment.htm>
More information about the users
mailing list