ShibRequestSetting forceAuthn true vs 1 vs on

Scott Cantor scott at restingparrotsoftware.com
Mon Jun 8 22:18:02 UTC 2026



> On Jun 8, 2026, at 4:27 PM, Dan McLaughlin <dmclaughlin at tech-consortium.com> wrote:
> 
> I found the problem.  We had maxTimeSinceAuthn=120. It's been like that since 2021, and we hadn't seen issues.

I assumed you meant the IdP was reporting a failure. An SP issue is a different matter, but that setting is about controlling use of old sessions, not limiting the risk of bearer token protocols.

The assertion is short lived regardless. If you want to control that transit limit, there are semi-obscure ways to do it (it's in the security-policy stuff essentially), but it isn't that setting.

-- Scott



More information about the users mailing list