<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<meta name="Generator" content="Microsoft Exchange Server">
<!-- converted from text --><style><!-- .EmailQuote { margin-left: 1pt; padding-left: 4pt; border-left: #800000 2px solid; } --></style>
</head>
<body>
<div>
<div>So how do I get the IdP to acknowledge the forceauthn?</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div><br>
</div>
<div>
<div style="font-size:100%">Sent from Samsung tablet</div>
</div>
<br>
&quot;Cantor, Scott&quot; &lt;cantor.2@osu.edu&gt; wrote:<br>
</div>
<font size="2"><span style="font-size:10pt;">
<div class="PlainText">On 8/14/14, 7:30 PM, &quot;Jesse Santana&quot; &lt;Jesse.Santana@csulb.edu&gt; wrote:<br>
<br>
&gt;The entire log entry looks like this:<br>
&gt;<br>
&gt;2014-08-14 16:27:53 INFO Shibboleth-TRANSACTION [3]: New session (ID:<br>
&gt;_e334e3c4ba1911df55847a371825edec) with (applicationId: default) for<br>
&gt;principal from (IdP: <a href="http://www.okta.com/kv79fg77CWVTMIVZXMLF">http://www.okta.com/kv79fg77CWVTMIVZXMLF</a>) at<br>
&gt;(ClientAddress: 134.139.2.14) with (NameIdentifier: 000020564) using<br>
&gt;(Protocol: urn:oasis:names:tc:SAML:2.0:protocol) from (AssertionID:<br>
&gt;id37166912858056794557589990)<br>
&gt;<br>
&gt;Which does get updated when I go to the application again:<br>
&gt;<br>
&gt;2014-08-14 16:29:11 INFO Shibboleth-TRANSACTION [5]: New session (ID:<br>
&gt;_e3f18b546f6524bb64232d748c9d62ca) with (applicationId: default) for<br>
&gt;principal from (IdP: <a href="http://www.okta.com/kv79fg77CWVTMIVZXMLF">http://www.okta.com/kv79fg77CWVTMIVZXMLF</a>) at<br>
&gt;(ClientAddress: 134.139.2.14) with (NameIdentifier: 000020564) using<br>
&gt;(Protocol: urn:oasis:names:tc:SAML:2.0:protocol) from (AssertionID:<br>
&gt;id377649452240692491450287841)<br>
<br>
That's a bit odd frankly, I don't know why you're getting a new session at<br>
all from opening a new tab, but assuming you are, then the IdP in question<br>
is ignoring the ForceAuthn setting. If so, it's doubly broken in that it's<br>
also apparently lying about the authentication timestamp.<br>
<br>
Cue Eric Goodman. ;-)<br>
<br>
It's probably worth tracing the messages and actually verifying what<br>
you're requesting and what they're sending.<br>
<br>
You can't set the SP's session lifetime to 5 seconds, that would be<br>
pathological unless you're not using the session locally for anything<br>
after it's created.<br>
<br>
-- Scott<br>
<br>
-- <br>
To unsubscribe from this list send an email to users-unsubscribe@shibboleth.net<br>
</div>
</span></font>
</body>
</html>