ShibIdP v4 & Azure SAML Authentication Issue with RequestedAuthnContext
Janusz Ulanowski
janusz.ulanowski at heanet.ie
Thu Jan 11 09:07:35 UTC 2024
We are using ShibIdP v4 as the IdP SAML proxy to Azure. It has been a while since I last worked on ShibIdP. Currently, I am trying to find a workaround for an issue that some users are experiencing.
When the IdP receives a SAML request from the Service Provider (SP) with RequestedAuthnContext and Comparison="exact," it passes that request to Azure. However, some browsers like Edge store the previous session and use X509 certificates with Azure IDP, leading to a validation failure due to an authRequest mismatch. The error on the Microsoft login site is AADSTS75011.
I am struggling to figure out how to override this behavior. Has anyone encountered a similar issue and found a fix for it?"
Thanks in advance
--
Janusz
More information about the users
mailing list