Authentication plugin for Shibboleth IDP 3

Cantor, Scott cantor.2 at osu.edu
Tue Dec 15 09:51:48 EST 2015


On 12/15/15, 7:15 AM, "dev on behalf of Marvin Addison" <dev-bounces at shibboleth.net on behalf of marvin.addison at gmail.com> wrote:



>Curious what "strong authentication" means to you. IdP 3.x ships with X509 client TLS auth support, and lots of deployers have developed 2-factor authentication without too much hassle. Do either of those help?

From the email address, I was assuming the interest was in supporting Symantec's token solution.

The best examples are probably the various plugins for Duo at this point, but of course right now the simple way to build/deploy second-factor flows is in conjunction with the Password flow as the "initial authentication" method, which causes trouble if you're also using X.509 or the like.

-- Scott



More information about the dev mailing list