<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex"><span class="">On 5/19/16, 11:11 AM, "users on behalf of Robert Lowe" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:robertmlowe@rmlowe.com">robertmlowe@rmlowe.com</a>> wrote:<br>
>Is this sufficient? What am I missing, or any better approach?<br>
<br>
</span>There's a way to statically enforce a limit on time elapsing since authn, but for your case that probably wouldn't work, so your application would have to do that. So that's about it I guess.<br></blockquote><div><br></div><div>Scott, you mean the <font face="monospace, monospace">maxTimeSinceAuthn</font> attribute on the <font face="monospace, monospace">Sessions</font> element? I did look at that, but as far as I could see it required defining a separate application (i.e an <font face="monospace, monospace">ApplicationOverride</font>), which seemed like overkill to me.</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left-width:1px;border-left-style:solid;border-left-color:rgb(204,204,204);padding-left:1ex">
<span class=""><br>
>(This is all assuming that the IdP supports<br>
>ForceAuthn, and is using an authentication method for which that has a reasonable interpretation.)<br>
<br>
</span>Which is a big assumption.<br></blockquote><div><br></div><div>Understood.</div><div></div></div><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr">Best regards,<br><br>Robert Lowe<br><a href="http://crepuscular.rmlowe.com/" target="_blank">http://crepuscular.rmlowe.com/</a></div></div>
</div></div>