[JIRA] (IDP-1896) Attempting to use authn-comparison to trigger MFA in SAML Auth Proxy for OIDC in addition to SAML for AuthnContext

Etan Weintraub (Jira) jira at shibboleth.atlassian.net
Thu Jan 13 14:30:39 UTC 2022


Etan Weintraub ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A16d3650e-1536-4bf4-894a-9efb8bacb163 ) *created* an issue

Identity Provider ( https://shibboleth.atlassian.net/browse/IDP?atlOrigin=eyJpIjoiZTEzOTYwMDViOWVkNDZjNjkwOTFjOWExZTljMTIxNGQiLCJwIjoiaiJ9 ) / Bug ( https://shibboleth.atlassian.net/browse/IDP-1896?atlOrigin=eyJpIjoiZTEzOTYwMDViOWVkNDZjNjkwOTFjOWExZTljMTIxNGQiLCJwIjoiaiJ9 ) IDP-1896 ( https://shibboleth.atlassian.net/browse/IDP-1896?atlOrigin=eyJpIjoiZTEzOTYwMDViOWVkNDZjNjkwOTFjOWExZTljMTIxNGQiLCJwIjoiaiJ9 ) Attempting to use authn-comparison to trigger MFA in SAML Auth Proxy for OIDC in addition to SAML for AuthnContext ( https://shibboleth.atlassian.net/browse/IDP-1896?atlOrigin=eyJpIjoiZTEzOTYwMDViOWVkNDZjNjkwOTFjOWExZTljMTIxNGQiLCJwIjoiaiJ9 )

Issue Type: Bug Affects Versions: 4.1.4 Assignee: Scott Cantor ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A5b78efc9-1379-42cc-a3f6-56c6ea3a0007 ) Components: Authentication, Configuration, OIDC Created: 13/Jan/22 9:30 AM Priority: Trivial Reporter: Etan Weintraub ( https://shibboleth.atlassian.net/secure/ViewProfile.jspa?accountId=557058%3A16d3650e-1536-4bf4-894a-9efb8bacb163 )

We are running into an issue with the authn-comparison.xml where we need to translate the OIDC Authn Context Class to something that Microsoft understands for use with MFA. This works currently with SAML2 protocols and it's AuthnContext, but when I try to add a second map for the OIDC one, the SAML2 one breaks, while OIDC works.

SAML2 Mapping:
<util:map id="shibboleth.PrincipalProxyRequestMappings">
<entry>
<key>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="https://refeds.org/profile/mfa" />
</key>
<list>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="http://schemas.microsoft.com/claims/multipleauthn" />
</list>
</entry>
</util:map>

OIDC Mapping:
<util:map id="shibboleth.PrincipalProxyRequestMappings">
<entry>
<key>
<bean parent="shibboleth.OIDCAuthnContextClassReference"
c:classRef="https://refeds.org/profile/mfa" />
</key>
<list>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="http://schemas.microsoft.com/claims/multipleauthn" />
</list>
</entry>
</util:map>

Response Mapping:
<util:map id="shibboleth.PrincipalProxyResponseMappings">
<entry>
<key>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="http://schemas.microsoft.com/claims/multipleauthn" />
</key>
<list>
<bean parent="shibboleth.SAML2AuthnContextClassRef"
c:classRef="https://refeds.org/profile/mfa" />
<bean parent="shibboleth.OIDCAuthnContextClassReference"
c:classRef="https://refeds.org/profile/mfa" />
</list>
</entry>
</util:map>

When I have just the SAML2 Request Map and the Response Map, everything works fine for SAML2. As soon as I add the OIDC Map, OIDC works fine, but SAML2 doesn't do the request mapping to change the context when sending up to Azure in the SAML Auth Proxy.

Help? This seems to be the only avenue I have for requiring MFA for some apps with OIDC and not all.

( https://shibboleth.atlassian.net/browse/IDP-1896#add-comment?atlOrigin=eyJpIjoiZTEzOTYwMDViOWVkNDZjNjkwOTFjOWExZTljMTIxNGQiLCJwIjoiaiJ9 ) Add Comment ( https://shibboleth.atlassian.net/browse/IDP-1896#add-comment?atlOrigin=eyJpIjoiZTEzOTYwMDViOWVkNDZjNjkwOTFjOWExZTljMTIxNGQiLCJwIjoiaiJ9 )

Get Jira notifications on your phone! Download the Jira Cloud app for Android ( https://play.google.com/store/apps/details?id=com.atlassian.android.jira.core&referrer=utm_source%3DNotificationLink%26utm_medium%3DEmail ) or iOS ( https://itunes.apple.com/app/apple-store/id1006972087?pt=696495&ct=EmailNotificationLink&mt=8 ) This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100188- sha1:ab29722 )
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/commits/attachments/20220113/189d4d67/attachment-0001.htm>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-comment-icon-4325e08d-4165-4397-a1c9-c153217d09ff
Type: image/png
Size: 1084 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220113/189d4d67/attachment-0004.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-trivial-4d396308-a159-4c88-9098-726c56849586
Type: image/png
Size: 563 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220113/189d4d67/attachment-0005.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-avatar-c988841f-0b58-4a12-b8bc-8e21b5175677
Type: image/png
Size: 425 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220113/189d4d67/attachment-0006.png>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: jira-generated-image-static-footer-desktop-logo-6b46fb5d-e80a-4f9c-8755-11b854b3b5dc
Type: image/png
Size: 10805 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/commits/attachments/20220113/189d4d67/attachment-0007.png>


More information about the commits mailing list