<div dir="ltr">After a recent Cherwell update we were seeing forced re-authentication as described. The Cherwell admins did find, after prodding, a setting in the SP to change to revert to honoring the SSO session. Cherwell regards this a feature:<div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Authentication is forced by default; this means Users are required to enter their credentials each time they access Cherwell. You may choose to disable Force Authentication.<br>Warning: We HIGHLY recommend you do not clear this option, as it has very serious security implications.</blockquote><div><br></div><div>We were able to turn off this behavior.</div><div><br></div><div>David Bantz </div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Thu, May 30, 2019 at 11:07 AM Cantor, Scott <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 5/30/19, 2:36 PM, "users on behalf of Garmer, Jack - garmercj" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:garmercj@jmu.edu" target="_blank">garmercj@jmu.edu</a>> wrote:<br>
<br>
> Because the SP is a GUI-based app on a windows server, there doesn’t appear to be an obvious setting to turn this off.<br>
> The product documentation also isn’t doing much for us. Is there a method on the IDP end to override forced reauth?<br>
<br>
I think you should at least verify that the cause is the SP including ForceAuthn and not some artifact of frames or a million other issues causing session recovery failure before moving to the next step.<br>
<br>
Assuming that's the case, there is no option right now to ignore what it says. There's an option to force it even if the SP can't ask for it, but that's the inverse.<br>
<br>
You can forcibly point the SP at a URL that is a rewrite script that ignores the original AuthnRequest and rewrites it into a new one that doesn't have ForceAuthn set, of course.<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a></blockquote></div>