Duo Forceauthn authn failure starting 2029-09-08
Brian Rose
brose at pointnclick.com
Mon Sep 14 15:31:13 UTC 2026
We have several Shibboleth IDP customers with Duo MFA, and since mid-day
last Tuesday 2029-09-08 two of them are reporting SSO failures when the end
user has an existing Shibboleth SSO session, and a login to a new SP with
forceauthn is sent.
We are seeing a authnfailure sent to the SP.
2026-09-08 14:18:24 (ET)
<saml2p:Status><saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:Requester"><saml2p:StatusCode
Value="urn:oasis:names:tc:SAML:2.0:status:AuthnFailed"/></saml2p:StatusCode><saml2p:StatusMessage>An
error occurred.</saml2p:StatusMessage></saml2p:Status>
Does anyone know if there were any default changes published just before
then? I am still working with the two IDPs that are experiencing this issue
to determine if anything was installed on their IDP systems which
correlate to this, and I have opened a ticket with Duo as well.
--
Brian Rose
Point and Click Solutions, Inc.
Chief Information Security Officer
916-800-2338
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20260914/26e37f65/attachment.htm>
More information about the users
mailing list