Bug in handling user certifications for specific contexts?

Cantor, Scott cantor.2 at osu.edu
Wed Sep 9 11:58:45 EDT 2015


On 9/9/15, 11:45 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:

>On 9/9/15, 11:22 AM, "dev on behalf of Wessel, Keith" <dev-bounces at shibboleth.net on behalf of kwessel at illinois.edu> wrote:
>
>>I suggested yesterday on the call that I had with the two Davids that it'd be nice if there was some way the IDP could be configured to know that before running Duo (or some other 2nd factor method), it must run password explicitly.

But also, I'm not saying there's not a bug. The FilterFlowsByAttribute action isn't like the FilterFlowsByForceAuthn action or some of the others that I copied it from, it isn't enough to just filter methods for selection, the system needs to be applying the same filtering to active results before it lets them get reused.

I'm just saying like all complex changes, it probably will have some unexpected effects that limit SSO in cases that aren't self-evident until they come up. But it can only fail safe, so it can't hurt that much.

-- Scott



More information about the dev mailing list