<p dir="ltr">Thanks again Scott. I&#39;ll pass on this information to the IdP.</p>
<div class="gmail_quote">On 31 Jul 2013 18:30, &quot;Cantor, Scott&quot; &lt;<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>&gt; wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 7/31/13 11:38 AM, &quot;Saimon Moore&quot; &lt;<a href="mailto:saimonmoore@gmail.com">saimonmoore@gmail.com</a>&gt; wrote:<br>
&gt;<br>
&gt;I put on my thinking cap and realised that I had forceAuthn set to true<br>
&gt;in shib2.xml config and this is why the existing session wasn&#39;t be reused.<br>
<br>
If their login handler chosen does not support ForceAuthn, then the IdP is<br>
behaving correctly by returning the error.<br>
<br>
&gt;So in reality I was asking the idp to reauthenticate while an existing<br>
&gt;session already existed. It may be that the IdP has an issue with this<br>
&gt;when the session cookies exist for the user retrying the authentication.<br>
<br>
No, the issue is they use a login handler that doesn&#39;t happen to support<br>
the option. Many will not.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>