OIDC refresh token and User Directory access in Policy Server
search cancel

OIDC refresh token and User Directory access in Policy Server

book

Article ID: 271345

calendar_today

Updated On:

Products

CA Single Sign On Agents (SiteMinder) CA Single Sign On Secure Proxy Server (SiteMinder) SITEMINDER

Issue/Introduction

 

When running CA Access Gateway (SPS) acting as a Provider, does the Policy Server still verify that the user still exists in the User Directory and will it verify if the password (login) will be attempted?

 

Resolution

 

At first glance, yes, the Policy Server will lookup the user from the User Directory configured, and it will check also the current user Session from the Session Store if there's one.

But it won't check the password. The password will only be checked when the user login the first time.