<div dir="ltr">Are the web user&#39;s cookies available to the authentication mechanism?  If they are then it would be fairly easy to determine that they have already logged on.</div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Dec 31, 2014 at 1:05 PM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">&gt; It probably is covered.<br>
<br>
Assuming Chris accurately understood the goal, no, the standard certainly doesn&#39;t cover that. Making it the private business of an authentication mechanism at the IdP is one way of doing something like that.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>