<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;"><div><div>Just after writing this I realise that what I suggested won’t fly in my own implementation.</div><div>In my proxy IdP I use a standard Shib V3 IdP to perform the IdP part, while the SP part of the proxy is running as an external Authn servlet.</div><div>And I don’t think there is any way I could forward the upstream AuthnInstant value to Shibboleth IdP anyway from the ExternalAuthn servlet.</div><div><br></div><div>So I guess every proxy have to decide their own time for AuthnInstant.</div><div><br></div><div>Correct me if I’m wrong here.</div><div><br></div><div>/Stefan</div><div><br></div><div><br></div><div><div id="MAC_OUTLOOK_SIGNATURE"></div></div></div><div><br></div><span id="OLK_SRC_BODY_SECTION"><div style="font-family:Calibri; font-size:12pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt"><span style="font-weight:bold">From: </span> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>> on behalf of Stefan Santesson <<a href="mailto:stefan@aaa-sec.com">stefan@aaa-sec.com</a>><br><span style="font-weight:bold">Reply-To: </span> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br><span style="font-weight:bold">Date: </span> Monday 9 November 2015 at 00:22<br><span style="font-weight:bold">To: </span> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br><span style="font-weight:bold">Subject: </span> What is the correct AuthnInstant value for a proxy IdP<br></div><div><br></div><blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;"><div><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 14px; font-family: Calibri, sans-serif;"><div>I’m using Shibboleth IdP and SP components in a cross-border pilot where several proxy IdP:s are involved.</div><div><br></div><div>I need help to figure out what each proxy IdP in the chain should claim as AuthnInstant.</div><div><br></div><div><br></div><div>For simplicity say that we have an auth chain with 2 proxy IdP like this:</div><div><br></div><div>SP  —> Proxy 1 —> Proxy 2 —> user IdP</div><div><br></div><div>Proxy 1 issues an assertion to SP, based on an assertion received by Proxy 2</div><div>Proxy 2 issues an assertion to Proxy 1 based on an assertion received from the user IdP.</div><div><br></div><div>Then what should Proxy 1 and Proxy 2 claim as AuthnInstant?</div><div><br></div><div>Should it attempt to preserve the AuthnInstant value received from the user IdP and forward it down the chain of assertions to the SP, or should they claim the time when they themselves received the proof of authentication.</div><div><br></div><div>This is is tricky business, but this example is exactly how the EU cross border identification is setup.</div><div><br></div><div><br></div><div>My thinking is. If the AuthnInstant is preserved through the chain, that would be the most honest option, and it would also detect if anyone in this chain is doing an SSO authentication instead of forwarding the request to the user IdP. The SP would then receive the time when the user actually used his credentials.</div><div><br></div><div>My fear is that this may break current SP code in some way. There may be some time delays in this chain caused by UI:s for user interaction when crossing country borders, such as giving consent to user data being transfered to a service provider in another country.</div><div>Forwarding the AuthnInstant may therefore cause situations where there are many seconds between issue instant and authn instant. Could this cause problems with existing SP softwares that requested ForceAuthn=“true” excepting issueInstant = AuthnInstant with no or tiny time difference?</div><div><br></div><div>I would like to preserve the AuthnInstant from the user IdP all the way to the SP, but I’m not sure it will fly.</div><div><br></div><div><br></div><div>/Stefan</div><div><br></div><div><br></div><div><br></div><span id="OLK_SRC_BODY_SECTION"><blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;"></blockquote></span><style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style></div></div>
-- 
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.net</a></blockquote></span></body></html>