<div dir="ltr"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">That isn't what the setting means, it applies to the policy to enforce at the time an assertion is accepted to make sure ForceAuthn was honored, and has nothing to do with sessions or timeouts. </blockquote><div><br></div><div>So, if an assertion from the IDP came in after the maxTimeSinceAuthn timeout the SP would then redirect to the IDP for a re-authentication?</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">You can't really be saying you want a 30 second timeout, but that's literally what you seem to be asking for here. I think you have not really explained what you want. But these settings are not how to do  it.</blockquote><div><br></div><div>Step one of what I'm after is to have a SAML protected resource that requires a re-authentication with the IDP anytime it's accessed. Basically, I want to disable SSO on this one resource. Would I simply set the sessions lifetime really low in addition to using forceAuthn and maxTimeSinceAuthn?<br></div><div><br></div><div>The bigger picture and where it, seems to, get complicated is that we want to have a shibboleth protected website (one virtual host) that has this one resource that requires authentication on every access, but the rest of the site with the "normal" timeouts, etc... Is this possible to do with only one ApplicationOverride and SP metadata? </div><div><br></div><div>Thanks</div><div><br></div><div> </div><div class="gmail_extra"><br><div class="gmail_quote">On Fri, May 5, 2017 at 10:32 AM, Cantor, Scott <span dir="ltr"><<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-">On 5/5/17, 6:52 AM, "users on behalf of Romeo Theriault" <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:romeotheriault@gmail.com">romeotheriault@gmail.com</a>> wrote:<br>
<br>
> I now have a need to force all subsequent requests to login to redirect the user back to the IDP to re-enter their credentials. I set<br>
> forceAuthn="true" in my ApplicationOverride SSO attribute and maxTimeSinceAuth="30" in the ApplicationOverride Sessions<br>
> attribute (see below). After I wait 30 (and more) seconds and go to relogin, I do not get sent back to the IDP and using network<br>
> tracing in chrome I see that the SP is not even re-requesting a re-auth from the IDP.<br>
<br>
</span>That isn't what the setting means, it applies to the policy to enforce at the time an assertion is accepted to make sure ForceAuthn was honored, and has nothing to do with sessions or timeouts. You can't really be saying you want a 30 second timeout, but that's literally what you seem to be asking for here. I think you have not really explained what you want. But these settings are not how to do  it.<br>
<span class="gmail-HOEnZb"><font color="#888888"><br>
-- Scott<br>
<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">users-unsubscribe@shibboleth.<wbr>net</a><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div dir="ltr"><div>Romeo Theriault<br></div></div></div>
</div></div>