Skip to content

IPSIE IdP Chaining #97

@deansaxe

Description

@deansaxe

Should IPSIE specify how this behaves in case of IdP chaining? I'm thinking more specifically of a setup like:

  • app1 federated to idp1
  • app2 federated to idp2
  • idp2 federated to idp1 (idp2 acting as a RP)
  • (this is an example of sharepoint federated to EntraID itself being federated to Okta)

If I first access to app1, I get authtime set to t0 by idp1 and sent to app1
If I then, 1 hour later, access to app2, idp1 should send t0 to idp2 (provided session is still on). Is that an authentication event from idp2 pov? Should app2 receive t0 or t0+1h?
IMHO app2 should receive t0 (except if idp2 does some additional MFA?) and IPSIE should require an IdP to transfer any authentication time it received if it's acting as both RP and IdP

Originally posted by @teddyber in #89

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions