<div dir="ltr"><div class="gmail_default" style="font-family:courier new,monospace">Okay sorry I reread you response, Basically all I'm asking is that if an SP requests forceAuthn we have a way to see that in the login.vm template, that way we can remove the checkbox to set donotcache since it's an irrelevant option for a forceAuthen service<br></div><div class="gmail_extra"><br clear="all"><div><div class="gmail_signature"><div dir="ltr"><font face="courier new, monospace">Jeffrey<a href="mailto:jeffreyc@ucsc.edu" target="_blank"></a></font><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div></div></div></div>
<br><div class="gmail_quote">On Fri, Aug 14, 2015 at 3:56 PM, Jeffrey Crawford <span dir="ltr"><<a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div style="font-family:courier new,monospace">If an SP makes a forceAuthn="true" request, we could ignore the fact that there is an option of donotcache.<br><br>That being the case, the option could be removed from the login page if we could inspect that kind of request.<br></div></div><div class="gmail_extra"><br clear="all"><div><div><div dir="ltr"><font face="courier new, monospace">Jeffrey E. Crawford<br>ITS Application Administrator (IdM)<br>831-459-4365<br><a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a></font><span class=""><div><font face="courier new, monospace"><br></font></div><div><font face="courier new, monospace">Both pilots and IT professionals require training and currency before charging into clouds!<br></font></div><div><font face="courier new, monospace">---------------------------------------</font></div></span></div></div></div><div><div class="h5">
<br><div class="gmail_quote">On Fri, Aug 14, 2015 at 3:43 PM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 8/14/15, 6:37 PM, "users on behalf of Jeffrey Crawford" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:jeffreyc@ucsc.edu" target="_blank">jeffreyc@ucsc.edu</a>> wrote:<br>
<br>
>There was a question around our campus regarding if it was possible to have the login page logic know if an SP requests forceAuthn and allow the login page not show the section of the form which sets donotcache. I didn't find anything however I'm sure I could have missed it as well.<br>
<br>
</span>If an SP requests ForceAuthn, the form would be used, but remembering the result after that is relevant for the following requests, not that one. So there is by definition nothing it could look at. Whether *that* request included it would have nothing to do with the decision to remember it for the next SP.<br>
<br>
Or perhaps I'm not following your line of thought.<br>
<span><font color="#888888"><br>
-- Scott<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</font></span></blockquote></div><br></div></div></div>
</blockquote></div><br></div></div>