ShibRequestSetting forceAuthn true vs 1 vs on
Dan McLaughlin
dmclaughlin at tech-consortium.com
Wed Jun 10 14:22:22 UTC 2026
I didn't look at the IDP logs yet, all I only know the error was thrown in
the SP logs, so it may have just been repeating what the IDP said was the
issue. When I changed the maxTimeSinceAuthn on the SP from 120, to 300 we
stopped getting all the calls and the errors.
--
Thanks,
Dan
On Mon, Jun 8, 2026 at 5:18 PM Scott Cantor <scott at restingparrotsoftware.com>
wrote:
>
>
> > On Jun 8, 2026, at 4:27 PM, Dan McLaughlin <
> dmclaughlin at tech-consortium.com> wrote:
> >
> > I found the problem. We had maxTimeSinceAuthn=120. It's been like that
> since 2021, and we hadn't seen issues.
>
> I assumed you meant the IdP was reporting a failure. An SP issue is a
> different matter, but that setting is about controlling use of old
> sessions, not limiting the risk of bearer token protocols.
>
> The assertion is short lived regardless. If you want to control that
> transit limit, there are semi-obscure ways to do it (it's in the
> security-policy stuff essentially), but it isn't that setting.
>
> -- Scott
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260610/e378f0e9/attachment.htm>
More information about the users
mailing list