Two-factor authentication and ApplicationOverride

Sérgio Nicolau da Silva sergions at gmail.com
Mon Sep 7 08:31:07 EDT 2015


Hi,

I am researching authentication with second factor.

The proposal is the use of ApplicationOverride (SP) setting a new Endpoint
(handlerURL) to second factor authentication. Where:
- Endpoint A (ApplicationDefaults):  user and password authentication;
- Endpoint B (ApplicationOverride): second factor authentication.

The IdP has a subflow for the second factor TOTP based.

The questions are:
- It is a viable way within the IdP / SP architecture?
- How to identify within the flow (SWF) the endpoint forward authentication
request, for to select the flow two-factor or password?

-- 
---------------------------------
Sérgio Nicolau da Silva
sergions at gmail.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/dev/attachments/20150907/31a609b8/attachment.html>


More information about the dev mailing list