Bug in handling user certifications for specific contexts?

Cantor, Scott cantor.2 at osu.edu
Wed Sep 9 11:45:01 EDT 2015


On 9/9/15, 11:22 AM, "dev on behalf of Wessel, Keith" <dev-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:

>I suggested yesterday on the call that I had with the two Davids that it'd be nice if there was some way the IDP could be configured to know that before running Duo (or some other 2nd factor method), it must run password explicitly.

I think the way to do that is to build one flow that does both, not try and trick that relationship into existence.

But that's why I suggested at one point that David have the Duo flow directly invoke the Password flow and consume the results rather than try and have the IdP coordinate it. That may or may not work in practice, but it does separate the flow implementations and theoretically allow for arbitrary use of particular flows in conjunction with it.

>Is there anything that can be done (or added) to tell a flow to first run another flow to get the needed principal before proceeding?

Sure, and it will have more unintended consequences, it's complexity on top of complexity, and people already can't handle what's there now. I don't think we're headed anywhere good with all this trying to generalize behaviors that just don't appear to generalize.

-- Scott



More information about the dev mailing list