Forced Authentication for SAML2 SPs

17 views
Skip to first unread message

Dustin Luck

unread,
Oct 12, 2021, 7:59:13 PM10/12/21
to CAS Community
I know that for SPs that use the CAS protocol, renew=true can be added to the URL by the client to do a "forced authentication". Is there any way that SAML2 SPs can do the same thing or does it need to be configured in the CAS service registry?

(CAS = 6.3.6)

Dustin Luck

unread,
Oct 15, 2021, 1:01:36 AM10/15/21
to CAS Community, Dustin Luck
I found the answer!

The SAML2 protocol supports an attribute in the AuthnRequest called 'ForceAuthn' that can be set to true to enable forced authentication. Fortunately, the SP I'm setting up supports it.
Reply all
Reply to author
Forward
0 new messages