IdP > SP TImestamps older than 30 days

Scott Cantor scott at restingparrotsoftware.com
Thu Sep 17 13:07:37 UTC 2026


Using that option is obviously...an option, but it is lying.

If you want to authenticate more often, then you do that I guess. Telling the SP the wrong information isn't, to me, proper behavior for an IdP. Far be it from me to defend them, as I'm usually not one to do so, but that's a pretty reasonable position on their part.

You can certainly control reuse of the result from the proxied method with a condition that differentiates based on the original SP if that's a requirement. Same for the result's lifetime/timeout now in 5.2 at least. There are ample controls available.

SAML doesn't have the max-age feature OpenID does, so that SP can't really be explicit about its requirements, it can only enforce after the fact (or use ForceAuthn).

-- Scott



More information about the users mailing list