ShibRequestSetting forceAuthn true vs 1 vs on
Dan McLaughlin
dmclaughlin at tech-consortium.com
Mon Jun 8 16:03:39 UTC 2026
Hey Scott,
I use all the default timeouts across the board and I couldn't find
anything that would explain a 2 minute timeout. Can you elaborate more on
the SameSite issue/mistake? You might be on to something, but I need to
know specifically what to look for.
--
Thanks,
Dan
On Fri, Jun 5, 2026 at 11:55 AM Scott Cantor <
scott at restingparrotsoftware.com> wrote:
>
>
> > On Jun 5, 2026, at 12:28 PM, Dan McLaughlin <
> dmclaughlin at tech-consortium.com> wrote:
> >
> > To clarify the timeout issue: it occurs when a user is proxied to the
> MFA provider and takes more than two minutes to enter their code and return
> to the SP. By that point, the SP session has expired, resulting in the
> error: "The gap between now and the time you logged into your identity
> provider exceeds the allowed limit."
>
> There is (mostly) no SP limit, I assume you mean the IdP. But that is not
> 2 minutes, it's more like 15 or more, though it's up to you what it is,
> that's set in web.xml or more often globally.
>
> Don't, FWIW, confuse SameSite issues with that. A SameSite mistake only
> breaks Chrome and that is 2 minutes.
>
> -- Scott
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260608/dcf918b6/attachment.htm>
More information about the users
mailing list