shibboleth-dev - Re: [Shib-Dev] Invalidating IdP Session
Subject: Shibboleth Developers
List archive
- From: Jim Fox <>
- To: "" <>
- Subject: Re: [Shib-Dev] Invalidating IdP Session
- Date: Wed, 1 Jul 2009 22:10:37 -0700
So your password change SP accepts an existing SSO session as sufficient identity proof that it will change a user's password, but then does not accept that same session as proof that the user is who he or she really is. The user must re-authenticate, using the password they just gave you, authenticated only by the old session, to get a new SSO session that is somehow more trustworthy? The usual dialog, which could be handled by your login plugin, says, "your old password; your new password." Why not let your login handler take care of the whole business? Jim |
- Invalidating IdP Session, Paul Hethmon, 07/01/2009
- Re: [Shib-Dev] Invalidating IdP Session, Chad La Joie, 07/02/2009
- Re: [Shib-Dev] Invalidating IdP Session, Paul Hethmon, 07/02/2009
- RE: [Shib-Dev] Invalidating IdP Session, Peter Williams, 07/04/2009
- Re: [Shib-Dev] Invalidating IdP Session, Jim Fox, 07/02/2009
- Re: [Shib-Dev] Invalidating IdP Session, Paul Hethmon, 07/02/2009
- Re: [Shib-Dev] Invalidating IdP Session, Chad La Joie, 07/02/2009
Archive powered by MHonArc 2.6.16.