reuse condition vs. maximumTimeSinceAuthn
Martin Leonhartsberger
m.leonhartsberger at cumulo.at
Wed Mar 20 10:49:04 UTC 2024
hi everyone,
I’m trying to setup following scenario:
SSO session lifetime on IDP PT4H.
exception for one SP with session lifetime PT30M (forceAuthn after that shorter period, enforced by IDP, not by SP forceAuthn Setting).
I came up with the profile setting for that p:maximumTimeSinceAuthn=”PT30M”, though log says in that case:
DEBUG [org.opensaml.saml.saml2.assertion.impl.AuthnStatementValidator:137] -Max time since authn for evaluation of AuthnStatement/@AuthnInstant not supplied, skipping
So I’m not sure if this useable at all because documentation refers to a proxied assertion.
Did I miss anything here?
I have the MFA authn flow in place, so the reuse condition could be a possibility as well (plugin of a function and check of the sp entity in the PRC).
But that would be plan b, since maximumTimeSinceAuthn sounds exactly like what I need.
best regards,
Martin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20240320/2630b592/attachment.htm>
More information about the users
mailing list