<div dir="ltr">Hi Scott,<div><br></div><div>Sorry to bother you again with this issue, but the people of the ADFS are blaming us that the double login it&#39;s our fault and not theirs (something that we think it&#39;s not true).</div><div><br></div><div><b>One question: </b>Since the ADFS it&#39;s always answering with the attribute ForceAuth = true in the SAML AuthRequest when we access their WS-Federation URL resource, can we do something to prevent the ForceAuth to appear or there&#39;s nothing that we can do (us meaning Shib&#39;s Idp) to avoid the re-force-auth?</div><div><br></div><div>Thanks again for all your help.</div><div><br></div><div>Best, </div></div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, Jan 23, 2015 at 9:24 AM, Cantor, Scott <span dir="ltr">&lt;<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>&gt;</span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">On 1/23/15, 1:02 PM, &quot;Thomas Jones&quot; &lt;<a href="mailto:thomas.jones.g@gmail.com">thomas.jones.g@gmail.com</a>&gt; wrote:<br>
<br>
<br>
&gt;<br>
&gt;1. Do you know if there&#39;s something that can be done on Shib&#39;s Idp side<br>
&gt;when it receives this SAML AuthnRequest (that has the ForceAuthn = true)<br>
&gt;and get from a session or a cookie info that can used to create a SAML<br>
&gt;Response that doesn&#39;t require to force the user to a whole authentication<br>
&gt;process (somehow a silent authentication)?<br>
<br>
</span>That would be a violation of the spec, but how you authenticate people is<br>
up to you in the end.<br>
<div class="HOEnZb"><div class="h5"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a><br>
</div></div></blockquote></div><br></div>