<div dir="ltr">Thanks for your comments.<div><br></div><div>We have discovered the problem, it was a misconfiguration in the authentication filter, it's ignoring the forceAuth parameter.</div><div><br></div><div>Bes regards.<br clear="all"><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><br><hr><span style="font-family:Verdana,Tahoma;font-size:11px;color:rgb(46,58,105)"><span style="font-weight:bold">Manolo García</span> <br>Arquitectura i Sistemes<br><span style="font-weight:bold">Universitat Oberta de Catalunya</span> <br></span> <br><span style="font-family:Verdana,Tahoma;font-size:11px;color:rgb(77,77,77)">93 326 (3451) | </span><font color="#4d4d4d" face="Verdana, Tahoma"><span style="font-size:11px">689 88 30 93 </span></font><span style="color:rgb(77,77,77);font-family:Verdana,Tahoma;font-size:11px">| </span><a href="mailto:mgarciaal@uoc.edu" style="font-family:Verdana,Tahoma;font-size:11px" target="_blank">mgarciaal@uoc.edu</a><span style="color:rgb(77,77,77);font-family:Verdana,Tahoma;font-size:11px"> </span></div><div dir="ltr"><span style="font-family:Verdana,Tahoma;font-size:11px;color:rgb(77,77,77)"><div dir="ltr"><div dir="ltr">Parc Mediterrani de la Tecnologia (edifici B3)</div><div dir="ltr">Av. Carl Friedrich Gauss, 5.</div><div dir="ltr">08860 Castelldefels</div></div></span><img alt="Universitat Oberta de Catalunya" src="http://cv.uoc.edu/WebMail/resources/img/UOC_e_mail.gif" style="border:medium none"> <br><span style="font-family:Verdana,Tahoma;font-size:10px;color:rgb(150,151,152)">Aquest missatge s'adreça exclusivament a qui va destinat i pot contenir informació privilegiada o confidencial i dades de caràcter personal, la difusió de les quals és regulada per la Llei orgànica de protecció de dades i la Llei de serveis de la societat de la informació. Si no sou la persona destinatària indicada (o la responsable de lliurar-lo a qui va destinat), no heu de copiar aquest missatge ni lliurar-lo a tercers per cap concepte. Si heu rebut aquest missatge per error o l'heu aconseguit per altres mitjans, us demanem que ens ho comuniqueu immediatament per aquesta mateixa via i l'elimineu irreversiblement.</span>  <br> <br><span style="font-family:Verdana,Tahoma;font-size:10px;color:rgb(150,151,152)">Abans d'imprimir aquest missatge electrònic penseu en el medi ambient.</span><br></div></div></div></div></div></div></div></div></div></div></div></div><br></div></div><br><div class="gmail_quote"><div dir="ltr">El mié., 19 dic. 2018 a las 11:45, Peter Schober (<<a href="mailto:peter.schober@univie.ac.at">peter.schober@univie.ac.at</a>>) escribió:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">* Manolo Garcia Alvarez <<a href="mailto:mgarciaal@uoc.edu" target="_blank">mgarciaal@uoc.edu</a>> [2018-12-19 08:54]:<br>
> Our problem is caused by this lack of synchrony: A CAS session may expire<br>
> much earlier than the Shibboleth session. We have tried to avoid the<br>
> problem using the forceAuthn in the SAML Request, but Shibboleth is not<br>
> behaving as expected and it's returning a CAS session that's expired.<br>
<br>
You're didn't mention the exact integration method between your Shib<br>
IDP and your CAS server. (I believe there are several ways to do this.)<br>
Probably that's just been done in a way that does not support<br>
forceAuthn (nor isPassive, I'm guessing)?<br>
<br>
Also note that the Shib IDP supports the CAS protocol itself and so<br>
you might get several benefits out of using that instead of having to<br>
run two separate SSO systems.<br>
<br>
-peter<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>