ShibRequestSetting forceAuthn true vs 1 vs on

Dan McLaughlin dmclaughlin at tech-consortium.com
Wed Jun 10 14:22:22 UTC 2026


I didn't look at the IDP logs yet, all I only know the error was thrown in
the SP logs, so it may have just been repeating what the IDP said was the
issue.  When I changed the maxTimeSinceAuthn on the SP from 120, to 300 we
stopped getting all the calls and the errors.

--

Thanks,

Dan

On Mon, Jun 8, 2026 at 5:18 PM Scott Cantor <scott at restingparrotsoftware.com>
wrote:

>
>
> > On Jun 8, 2026, at 4:27 PM, Dan McLaughlin <
> dmclaughlin at tech-consortium.com> wrote:
> >
> > I found the problem.  We had maxTimeSinceAuthn=120. It's been like that
> since 2021, and we hadn't seen issues.
>
> I assumed you meant the IdP was reporting a failure. An SP issue is a
> different matter, but that setting is about controlling use of old
> sessions, not limiting the risk of bearer token protocols.
>
> The assertion is short lived regardless. If you want to control that
> transit limit, there are semi-obscure ways to do it (it's in the
> security-policy stuff essentially), but it isn't that setting.
>
> -- Scott
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260610/e378f0e9/attachment.htm>


More information about the users mailing list