mitigating the effects of forceAuthn terrorism

Timo Tunturi timo.tunturi at aalto.fi
Thu Apr 9 09:42:43 UTC 2026


Hi,

Is there a way to sandbox an authn request with forceAuthn so that the 
results of that authentication would not affect the global session at all?

The scenario to avoid would be one where the user has authenticated with 
a stronger mechanism like WebAuthn and a SP asks for forceAuthn. In the 
worst case scenario with specifically the password method on top.

The end result is awkward where the user re-authenticates with a 
weak/vulnerable mechanism and his global session gets downgraded to that 
mechanism as well.

At least conceptually I don't see why an authn request with forceAuthn 
would have to effectively do local SLO at the same time.

-- Timo Tunturi / Aalto University IT


More information about the users mailing list