You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

CUWebAuthShibboleth(shib.conf)Shibboleth(shibboleth2.xml)
AuthName CornellDelete it 
AuthType all

AuthType shibboleth

ShibRequestSetting requireSession 1

 
Require valid-userRequire valid-user 
Require netid netid1 netid2

Require  shib-attr uid netid1 netid2

 
Require  permit myPermitRequire  shib-attr groups myPermit 
Require nopromptNot supported 
CUWA2FARequire allShibRequestSetting authnContextClassRef http://cornell.edu/mfa 
CUWA2FARequire permit-name1 permit-name2Not supported in Shibboleth SP. 
CUWACredentialAge <Sessions lifetime= ... >
CUWAinactivityTimeout <Sessions  ... timeout=...>
Combination of CUWACredentialAge and CUWAinactivityTimeout for the purpose of forcing user re-loginShibRequestSetting forceAuthn true 
  • No labels