Skip to content

Commit f2e1c0f

Browse files
committed
Add info on enforceChannelBinding setting
1 parent db22b29 commit f2e1c0f

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

docs/negotiate.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -207,11 +207,14 @@ To prevent this, certificate-based channel binding is supported by this module a
207207
Syntax for this is:
208208

209209
```php
210+
'enforceChannelBinding' => true,
210211
'allowedCertificateHashes' => [<SHA-256 finterprint 1>, <SHA-256 fingerprint 2>],
211212
```
212213

213214
Usually this array will contain just the one fingerprint for the current HTTPS-certificate of this IdP, but multiple can be
214215
used in a certificate-rollover situation.
216+
If the `enforceChannelBinding` setting is set to `true`, clients that do not provide binding-info will automatically be sent
217+
to the fallback authsource.
215218

216219
### Logout/Login loop and reauthenticating
217220

0 commit comments

Comments
 (0)