Just invoke the requireTgt transition if a renew parameter is detected so that that portion of the cas protocol is honored. Right now if there is an existing CAS non-mfa session and a service sends back the authn_method=MFA-YOUR-METHOD-HERE in conjunction with renew=true the renew parameter is ignored and it just drops them on the second factor authentication screen. Only added renew as supporting gateway in conjunction with authn_method doesn't make sense in my head.
Just invoke the requireTgt transition if a renew parameter is detected so that that portion of the cas protocol is honored. Right now if there is an existing CAS non-mfa session and a service sends back the
authn_method=MFA-YOUR-METHOD-HERE
in conjunction withrenew=true
the renew parameter is ignored and it just drops them on the second factor authentication screen. Only added renew as supportinggateway
in conjunction withauthn_method
doesn't make sense in my head.