Assurance Enhancements for IdPv2

William G. Thompson, Jr. wgthom at gmail.com
Tue May 21 09:05:02 EDT 2013


On Fri, May 17, 2013 at 4:48 PM, Tom Scavo <trscavo at gmail.com> wrote:
> Hi Bill,
>
> On Fri, May 17, 2013 at 3:00 PM, William G. Thompson, Jr.
> <wgthom at gmail.com> wrote:
>>
>> Any other thoughts on potential implementation paths...
>
> One thought is to separate the two factors such that the second factor
> is handled by the Unicon post-login handler. In this way, user
> attributes would be available to the post-login handler so that user
> consent could occur in conjunction with authentication via the second
> factor (two birds with one stone :)

The RFP requires two methods for presenting possible
AuthNContexts/Methods and more sophisticated behavior than static MFA,
not sure we can achieve all of that at post-login time.

Best,
Bill


>
> Let me give an explicit example. Suppose the second factor is Duo
> Push. The post-login handler could pass the resolved user attributes
> to the Duo Service so that they are displayed on the user's mobile
> device. In effect, the user approves the authentication step and
> attribute release at the same time. Since Duo Push depends on a
> public-private key pair, the attributes could even be encrypted in
> transit.
>
> Just a thought,
>
> Tom
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net


More information about the dev mailing list