ShibRequestSetting forceAuthn true vs 1 vs on

Dan McLaughlin dmclaughlin at tech-consortium.com
Thu Jun 4 19:59:56 UTC 2026


I am looking for clarification regarding the behavior of forceAuthn within
SP 3, Embedded DS, and IDP 5.1.x.

According to the SP documentation, the values "1", "true", and "On" should
be interchangeable for boolean settings. However, we recently encountered
an issue where setting ShibRequestSetting forceAuthn on caused users to get
stuck in a loop if they took too long to complete MFA, resulting in the
error: "The gap between now and the time you logged into your identity
provider exceeds the allowed limit."

Changing the configuration to ShibRequestSetting forceAuthn true resolved
the issue, and the IDP now correctly forces authentication, breaking the
loop.

Could someone familiar with the internals of these components explain why
"on" and "true" appear to behave differently in this context? I would like
to know if this is a known bug or if I am misinterpreting the documentation.

Thanks,

Dan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260604/26b90c46/attachment.htm>


More information about the users mailing list