ShibRequestSetting forceAuthn true vs 1 vs on

Dan McLaughlin dmclaughlin at tech-consortium.com
Mon Jun 8 16:05:46 UTC 2026


This issue?
https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199501597/SameSite

--

Thanks,

Dan =

On Mon, Jun 8, 2026 at 11:03 AM Dan McLaughlin <
dmclaughlin at tech-consortium.com> wrote:

> Hey Scott,
>
> I use all the default timeouts across the board and I couldn't find
> anything that would explain a 2 minute timeout.   Can you elaborate more on
> the SameSite issue/mistake?    You might be on to something, but I need to
> know specifically what to look for.
>
> --
>
> Thanks,
>
> Dan
>
> On Fri, Jun 5, 2026 at 11:55 AM Scott Cantor <
> scott at restingparrotsoftware.com> wrote:
>
>>
>>
>> > On Jun 5, 2026, at 12:28 PM, Dan McLaughlin <
>> dmclaughlin at tech-consortium.com> wrote:
>> >
>> > To clarify the timeout issue: it occurs when a user is proxied to the
>> MFA provider and takes more than two minutes to enter their code and return
>> to the SP. By that point, the SP session has expired, resulting in the
>> error: "The gap between now and the time you logged into your identity
>> provider exceeds the allowed limit."
>>
>> There is (mostly) no SP limit, I assume you mean the IdP. But that is not
>> 2 minutes, it's more like 15 or more, though it's up to you what it is,
>> that's set in web.xml or more often globally.
>>
>> Don't, FWIW, confuse SameSite issues with that. A SameSite mistake only
>> breaks Chrome and that is 2 minutes.
>>
>> -- Scott
>>
>>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260608/12da61c1/attachment.htm>


More information about the users mailing list