-
Notifications
You must be signed in to change notification settings - Fork 4
max_age and auth_time #4
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Updated to address needs of FAL2.
|
For reference: max_age |
Follow up from discussion on June 17, 2025 call. Updated the requirements to mandate the OP process the `max_age` property. If the elapsed time since authN is < `max_age`, the OP MAY force reauthentication. If the elapsed time is > `max_age`, the OP MUST force reauthentication.
Updated to make it optional for the RP to send the `max_age` parameter.
Removed trailing spaces.
|
I missed the call on Jul 1 so don't know if this is resolved or not. I think we need to define what is meant my "end user authentication" (i.e. did the user need to do something? or is a silent authentication sufficient?). The OpenID Connect spec text also seems to imply ensuring that the authentication ensures the End-User is the same human who originally authenticated. I'm not sure we have good ways to do that other than biometric based challenges. Maybe we can define this to mean that sufficient verification is performed by the OP to ensure that authentication methods bound to the identity associated with the session have been successfully completed. |
|
@gffletch see the notes from July 1. We determined that the This is an example and may not be acceptable syntax, but it should give you an idea of what we're thinking about. I'm open to other ideas of how to represent the mapping of 2..n |
Updated to address needs of FAL2 in openid/ipsie#90 and openid/ipsie#89.