<p dir="ltr">Thanks again Scott. I'll pass on this information to the IdP.</p>
<div class="gmail_quote">On 31 Jul 2013 18:30, "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br type="attribution"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
On 7/31/13 11:38 AM, "Saimon Moore" <<a href="mailto:saimonmoore@gmail.com">saimonmoore@gmail.com</a>> wrote:<br>
><br>
>I put on my thinking cap and realised that I had forceAuthn set to true<br>
>in shib2.xml config and this is why the existing session wasn't be reused.<br>
<br>
If their login handler chosen does not support ForceAuthn, then the IdP is<br>
behaving correctly by returning the error.<br>
<br>
>So in reality I was asking the idp to reauthenticate while an existing<br>
>session already existed. It may be that the IdP has an issue with this<br>
>when the session cookies exist for the user retrying the authentication.<br>
<br>
No, the issue is they use a login handler that doesn't happen to support<br>
the option. Many will not.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>