<div dir="ltr">Are the web user's cookies available to the authentication mechanism? If they are then it would be fairly easy to determine that they have already logged on.</div><div class="gmail_extra"><br><div class="gmail_quote">On Wed, Dec 31, 2014 at 1:05 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">> It probably is covered.<br>
<br>
Assuming Chris accurately understood the goal, no, the standard certainly doesn't cover that. Making it the private business of an authentication mechanism at the IdP is one way of doing something like that.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>